CVE-2026-3862 PUBLISHED

Cross-Site Scripting Vulnerability in SiteMinder Administrative UI

Assigner: symantec
Reserved: 10.03.2026 Published: 10.03.2026 Updated: 10.03.2026

Cross-site Scripting (XSS) allows an attacker to submit specially crafted data to the application which is returned unaltered in the resulting web page.

Metrics

CVSS Vector: CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:A/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N/AU:N/R:A/RE:M/U:Green
CVSS Score: 4.6

Product Status

Vendor Broadcom
Product SiteMinder
Versions Default: unaffected
  • Version 12.9 is affected
  • Version 12.8.x is affected

References

Impacts

  • CAPEC-63 Cross-Site Scripting (XSS)