CVE detail
CVE-2009-2704 — CVE-2009-2704
Published 2009-08-11 · Modified 2026-06-16 · Vendor sun · Product j2ee · Source nvd
UNKNOWN
severity
CVSS-derived band
0.0395
EPSS probability
exploitation probability, 30d
89.0%
EPSS percentile
percentile vs all CVEs
NOT LISTED
CISA KEV
known exploited catalog
Description
CA SiteMinder allows remote attackers to bypass cross-site scripting (XSS) protections for J2EE applications via a request containing a %00 (encoded null byte).
Remediation
No vendor-published fix data in our corpus for this CVE. Check the references below or the vendor's PSIRT / security advisories page.
References