Netegrity developed identity and access management solutions including SiteMinder, IdentityMinder, and related policy servers that were widely deployed in enterprise single sign-on and web access control architectures. The vendor's vulnerability profile, though modest in volume, shows a notable tendency toward public exploit availability across its access-control and authentication products. Current exploitation activity, severity distribution, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Netegrity over time
Signals from CVEs in this vendor scope (6 CVEs).
6 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2004-0672MEDIUM Multiple cross-site scripting (XSS) vulnerabilities in the primary and management web interfaces in Netegrity IdentityMinder Web Edition 5.6 allows remote attackers to execute scri | Aug 6, 2004 | 6.8 | 27 | NO | YES |
CVE-2004-0425HIGH Heap-based buffer overflow in SiteMinder Affiliate Agent 4.x allows remote attackers to execute arbitrary code via a large SMPROFILE cookie. | Aug 18, 2004 | 10.0 | 26 | NO | NO |
CVE-2003-1311MEDIUM siteminderagent/SmMakeCookie.ccc in Netegrity SiteMinder does not ensure that the TARGET parameter names a valid redirection resource, which allows remote attackers to construct a | Dec 31, 2003 | 6.8 | 23 | NO | NO |
CVE-2001-1455HIGH Netegrity SiteMinder 3.6 through 4.5.1 allows remote attackers to bypass filtering via URLs containing Unicode characters. | Aug 24, 2001 | 7.5 | 20 | NO | NO |
CVE-2000-0850HIGH Netegrity SiteMinder before 4.11 allows remote attackers to bypass its authentication mechanism by appending "$/FILENAME.ext" (where ext is .ccc, .class, or .jpg) to the requested | Nov 14, 2000 | 7.5 | 19 | NO | NO |
CVE-2003-1312MEDIUM siteminderagent/SmMakeCookie.ccc in Netegrity SiteMinder places a session ID string in the value of the SMSESSION parameter in a URL, which might allow remote attackers to obtain t | Dec 31, 2003 | 4.3 | 14 | NO | NO |
Signals from CVEs in this vendor scope (6 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Netegrity.
Media articles that mention a CVE ID that affects a product developed by Netegrity — matched by CVE ID, not by vendor name.