cvedb.io
CVE-2015-6854
CRITICAL · CVSS 9.1
EPSS exploitation probability: 0%
Published 2016-03-24T01:59:02.293 · Last modified 2026-06-17T00:31:32.010

Summary

The non-Domino web agents in CA Single Sign-On (aka SSO, formerly SiteMinder) R6, R12.0 before SP3 CR13, R12.0J before SP3 CR1.2, and R12.5 before CR5 allow remote attackers to cause a denial of service (daemon crash) or obtain sensitive information via a crafted request.

Affected products

broadcom — single_sign-on

Does this affect you?

Add your gear to cvedb and we'll alert you only when broadcom ships something exploited.

Check my exposure →

References

This product uses data from the NVD API but is not endorsed or certified by the NVD. Informational only; not professional security advice.