> List: bugtraq
> Subject: SiteMinder Multiple Vulnerabilities
> From: c0ntex <c0ntexb () gmail ! com>
> Date: 2005-07-08 14:03:11
>
> $ An open security advisory #10 - Siteminder v5.5=20
> Vulnerabilities
>
> [...]


This issue is NOT present in out-of-the-box installations of=20
SiteMinder. All supported versions of SiteMinder have an
agent configuration parameter called "CSSChecking" that is,
by default, set to "YES". A SiteMinder administrator would=20
have to intentionally set this parameter to "NO" to become=20
vulnerable to this issue.

The "CSSChecking" configuration parameter has been very well=20
documented in SiteMinder product documentation since 2001.

This issue is also documented and addressed in a security=20
advisory posted in October 2002 at this URL:
(URL may wrap)
https://support.netegrity.com/ocp/cu...roductdownload
..asp?isNodeGroup=3Dnull&ProductNumber=3D735&Pare =
ntId=3D493&groupType=3D249

Note that SiteMinder customers should continue to go to=20
support.netegrity.com for product support.

Regards,
kw
=20
Ken Williams ; Vulnerability Research=20
Computer Associates ; 0xE2941985
A9F9 44A6 B421 FF7D 4000 E6A9 7925 91DF E294 1985