- Description
- The Domino web agent in CA Single Sign-On (aka SSO, formerly SiteMinder) R6, R12.0 before SP3 CR13, R12.0J before SP3 CR1.2, R12.5 before CR5, R12.51 before CR4, and R12.52 before SP1 CR3 allows remote attackers to cause a denial of service (daemon crash) or obtain sensitive information via a crafted request.
- Source
- cve@mitre.org
- NVD status
- Modified
CVSS 3.0
- Type
- Primary
- Base score
- 9.1
- Impact score
- 5.2
- Exploitability score
- 3.9
- Vector string
- CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H
- Severity
- CRITICAL
CVSS 2.0
- Type
- Primary
- Base score
- 6.4
- Impact score
- 4.9
- Exploitability score
- 10
- Vector string
- AV:N/AC:L/Au:N/C:P/I:N/A:P
- nvd@nist.gov
- CWE-345
- Hype score
- Not currently trending
[
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:a:broadcom:single_sign-on:r6.0:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "582FBE95-BEBF-493F-AD4E-F037D6BED676"
},
{
"criteria": "cpe:2.3:a:broadcom:single_sign-on:r12.0:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "8547CFA2-7EE5-4ACD-B674-E5A79BAA7386"
},
{
"criteria": "cpe:2.3:a:broadcom:single_sign-on:r12.0j:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "4B4AADB6-1383-46FD-B280-A38DB34CDD9E"
},
{
"criteria": "cpe:2.3:a:broadcom:single_sign-on:r12.5:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "64912372-5719-4BCE-8FB6-866314E5488D"
},
{
"criteria": "cpe:2.3:a:broadcom:single_sign-on:r12.51:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "289FC857-0097-450C-8265-67BDD03BCD8C"
},
{
"criteria": "cpe:2.3:a:broadcom:single_sign-on:r12.52:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "AF9771F9-0693-4D3F-9C60-CD1E3E5D5267"
}
],
"operator": "OR"
}
]
}
]