Vulnerabilities (CVE)

Filtered by vendor Broadcom Subscribe
Filtered by product Symantec Siteminder
Total 2 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2026-3862 1 Broadcom 1 Symantec Siteminder 2026-05-07 N/A 4.8 MEDIUM
Cross-site Scripting (XSS) allows an attacker to submit specially crafted data to the application which is returned unaltered in the resulting web page.
CVE-2005-10001 1 Broadcom 1 Symantec Siteminder 2024-11-20 5.8 MEDIUM 5.4 MEDIUM
A vulnerability was found in Netegrity SiteMinder up to 4.5.1 and classified as critical. Affected by this issue is the file /siteminderagent/pwcgi/smpwservicescgi.exe of the component Login. The manipulation of the argument target leads to an open redirect. The exploit has been disclosed to the public and may be used. NOTE: This vulnerability only affects products that are no longer supported by the maintainer