Vulnerability Description
The non-Domino web agents in CA Single Sign-On (aka SSO, formerly SiteMinder) R6, R12.0 before SP3 CR13, R12.0J before SP3 CR1.2, and R12.5 before CR5 allow remote attackers to cause a denial of service (daemon crash) or obtain sensitive information via a crafted request.
CVSS Score
CRITICAL
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Broadcom | Single Sign-On | r6.0 |
Related Weaknesses (CWE)
References
- http://www.ca.com/us/support/ca-support-online/product-content/recommended-readiVendor Advisory
- http://www.securitytracker.com/id/1035389
- http://www.ca.com/us/support/ca-support-online/product-content/recommended-readiVendor Advisory
- http://www.securitytracker.com/id/1035389
FAQ
What is CVE-2015-6854?
CVE-2015-6854 is a vulnerability with a CVSS score of 9.1 (CRITICAL). The non-Domino web agents in CA Single Sign-On (aka SSO, formerly SiteMinder) R6, R12.0 before SP3 CR13, R12.0J before SP3 CR1.2, and R12.5 before CR5 allow remote attackers to cause a denial of servi...
How severe is CVE-2015-6854?
CVE-2015-6854 has been rated CRITICAL with a CVSS base score of 9.1/10. This is considered a critical vulnerability requiring immediate attention.
Is there a patch for CVE-2015-6854?
Check the references section above for vendor advisories and patch information. Affected products include: Broadcom Single Sign-On.