CVE-2024-36459: Broadcom Symantec Siteminder
High severity, CVSS 8.4. EPSS: 0.4% chance of exploitation in the next 30 days.
A CRLF cross-site scripting vulnerability has been identified in certain configurations of the SiteMinder Web Agent for IIS Web Server and SiteMinder Web Agent for Domino Web Server. As a result, an attacker can execute arbitrary Javascript code in a client browser.
Affected products
- Broadcom Symantec Siteminder: up to and including 12.52; version R12.8 only; up to and including r12.52_sp1_cr11
Published 2024-06-14. Last modified 2026-06-17.