A CRLF cross-site scripting vulnerability has been identified in certain configurations of the SiteMinder Web Agent for IIS Web Server and SiteMinder Web Agent for Domino Web Server. As a result, an attacker can execute arbitrary Javascript code in a client browser.
CVSS
No CVSS.
References
Configurations
No configuration.
History
21 Nov 2024, 09:22
Type | Values Removed | Values Added |
---|---|---|
References | () https://datatracker.ietf.org/doc/html/rfc6265#section-4.1.1 - | |
References | () https://support.broadcom.com/web/ecx/support-content-notification/-/external/content/SecurityAdvisories/0/24537 - |
03 Jul 2024, 02:03
Type | Values Removed | Values Added |
---|---|---|
CWE | CWE-93 |
17 Jun 2024, 12:42
Type | Values Removed | Values Added |
---|---|---|
Summary |
|
14 Jun 2024, 12:15
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2024-06-14 12:15
Updated : 2024-11-21 09:22
NVD link : CVE-2024-36459
Mitre link : CVE-2024-36459
CVE.ORG link : CVE-2024-36459
JSON object : View
Products Affected
No product.
CWE
CWE-93
Improper Neutralization of CRLF Sequences ('CRLF Injection')