Siteminder
This hub aggregates every CVE we track for Siteminder, a product in the cloud saas space. Use it to gauge the current risk picture and drill into individual advisories.
8
CVEs tracked
0
Critical
2
High
0
In CISA KEV
Severity distribution
MEDIUM6HIGH2
Monthly trend
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
1
0
0
0
0
2024-082026-07
Latest CVEs
The 8 most recently published vulnerabilities affecting Siteminder.
- CVE-2026-3862Cross-Site Scripting Vulnerability in SiteMinder Administrative UI4.8
- CVE-2005-10001Netegrity SiteMinder Login smpwservicescgi.exe redirect5.4
- CVE-2013-5968Cross-site scripting (XSS) vulnerability in CA SiteMinder 12.0 through 12.51, and SiteMinder 6 Web Agents, allows remote attackers to inject arbitrary web script or HTML via vectors involving a " (...4.3
- CVE-2011-4054Cross-site scripting (XSS) vulnerability in login.fcc in CA SiteMinder R6 SP6 before CR7 and R12 SP3 before CR8 allows remote attackers to inject arbitrary web script or HTML via the postpreservati...4.3
- CVE-2011-1718The Web Agents component in CA SiteMinder R6 before SP6 CR2 and R12 before SP3 CR2 does not properly handle multi-line headers, which allows remote authenticated users to conduct impersonation atta...4.3
- CVE-2009-2705CA SiteMinder allows remote attackers to bypass cross-site scripting (XSS) protections for J2EE applications via a request containing non-canonical, "overlong Unicode" in place of blacklisted chara...4.3
- CVE-2001-1455Netegrity SiteMinder 3.6 through 4.5.1 allows remote attackers to bypass filtering via URLs containing Unicode characters.7.5
- CVE-2000-0850Netegrity SiteMinder before 4.11 allows remote attackers to bypass its authentication mechanism by appending "$/FILENAME.ext" (where ext is .ccc, .class, or .jpg) to the requested URL.7.5
Product normalization is registry-driven with AI assist and human review. How it works