Posted by Williams, James K on Apr 20
CA20110420-01: Security Notice for CA SiteMinder
Issued: April 20, 2011
CA Technologies support is alerting customers to a security risk
associated with CA SiteMinder. A vulnerability exists that can allow a
malicious user to impersonate another user. CA Technologies has
issued patches to address the vulnerability.
The vulnerability, CVE-2011-1718, is due to improper handling of
multi-line headers. A malicious user can send specially…




