Siteminder adminUI -- Vulnerable Version - jQuery Datatables CVE-2015-6584 CVE-2021-36713
search cancel

Siteminder adminUI -- Vulnerable Version - jQuery Datatables CVE-2015-6584 CVE-2021-36713

book

Article ID: 403548

calendar_today

Updated On:

Products

SITEMINDER

Issue/Introduction

Your security team may report vulnerabilities of CVE-2015-6584 CVE-2021-36713 for following adminUI URLs,

http://<adminUI host>:8080/iam/siteminder/resources/fedmgr/javascript/jquery.dataTables.min.js

https://<adminUI host>:8443/ca/api/sso/services/v1/api-doc/swagger-ui-bundle.js

 

 

Resolution

CVE-2015-6584 is specific to Android webView, and CVE-2021-36713 is specific to the downloading of microsoft docx.

Hence the js files on adminUI website are not impacted by those CVEs.