Vulnerabilities > CVE-2000-0850 - Unspecified vulnerability in Netegrity Siteminder 3.6/4.0

047910
CVSS 7.5 - HIGH
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
PARTIAL
Integrity impact
PARTIAL
Availability impact
PARTIAL
network
low complexity
netegrity

Summary

Netegrity SiteMinder before 4.11 allows remote attackers to bypass its authentication mechanism by appending "$/FILENAME.ext" (where ext is .ccc, .class, or .jpg) to the requested URL.

Vulnerable Configurations

Part Description Count
Application
Netegrity
2