CA20110420-01: Security Notice for CA SiteMinder - CA Technologies
{{search ? 'Close':'Search'}}

CA20110420-01: Security Notice for CA SiteMinder

Issued: April 20, 2011
Last Updated: May 19, 2011

CA Technologies support is alerting customers to a security risk associated with CA SiteMinder. A vulnerability exists that can allow a malicious user to impersonate another user. CA Technologies has issued patches to address the vulnerability.

The vulnerability, CVE-2011-1718, is due to improper handling of multi-line headers. A malicious user can send specially crafted data to impersonate another user.

Risk Rating




Affected Products

CA SiteMinder R6 IIS 6.0 Web Agents prior to R6 SP6 CR2
CA SiteMinder R12 IIS 6.0 Web Agents prior to R12 SP3 CR2

How to determine if the installation is affected

Check the Web Agent log to obtain the installed release version. Note that the "webagent.log" file name is configurable by the SiteMinder administrator.


CA has issued patches to address the vulnerability.

CA SiteMinder R6:
Upgrade to R6 SP6 CR2 or later

CA SiteMinder R12:
Upgrade to R12 SP3 CR2 or later

CR releases can be found on the CA SiteMinder Hotfix/Cumulative Release page:


CVE-2011-1718 - CA SiteMinder Multi-line Header Vulnerability


April King (

Change History

Version 1.0: Initial Release
Version 1.1: Updated Affected Products section to clarify that only the IIS 6.0 Web Agents are affected. IIS 7 is not affected by this issue.

If additional information is required, please contact CA Technologies Support at

If you discover a vulnerability in a CA Technologies product, please report your findings to the CA Technologies Product Vulnerability Response Team.

Chat with CA

Just give us some brief information and we'll connect you to the right CA Expert.

Our hours of availability are 8AM - 5PM CST.

All Fields Required


We're matching your request.

Unfortunately, we can't connect you to an agent. If you are not automatically redirected please click here.

  • {{}} will be helping you today.

    View Profile

  • Transfered to {{}}

    {{}} joined the conversation

    {{}} left the conversation

  • Your chat with {{$storage.chatSession.messages[$index - 1]}} has ended.
    Thank you for your interest in CA.

    How Did We Do?
    Let us know how we did so that we can maintain a quality experience.

    Take Our Survey >

agent is typing