The Siteminder Policy Server bundles Libcurl in the binaries. The following versions of Libcurl are shipped with the Siteminder Policy Server:
Policy Server r12.8.7: LibCurl 7.84.0
Policy Server r12.8.8: LibCurl 8.4.0
Policy Server r12.8.8.1: LibCurl 8.4.0
Policy Server r12.9: LibCurl 8.12.1.0
KB378171 delivered LibCurl 8.10.0
NOTE: This KB only applies to Siteminder Policy Server r12.8.8.1 and older. For the 12.9 Policy Servers use KB 437711 Vulnerability in Libcurl 8.17.0 and older in the Siteminder Policy Server r12.9 and older
PRODUCT: Symantec Siteminder
COMPONENT: Policy Server
VERSIONS: r12.8.7; r12.8.8; r12.8.8.1
OPERATING SYSTEM: Any
The following CVE's have been published for LibCurl 7.84.0 - 8.18.0.
Using this KB you can upgrade LibCurl on the r12.8.8.1 and older Siteminder Policy Server to LibCurl 8.17.0. LibCurl 8.17.0 has been attached to this KB.
It is advised that to remediate all LibCurl CVE's you upgrade the Siteminder Policy Server to r12.9 or higher.
Siteminder r12.8.8.1 and older along with LibCurl 8.17.0 and older are both built on OpenSSL 1.0.2. Siteminder r12.9 and higher along with LibCurl 8.18.0 and higher are both built on OpenSSL 3.0.x. Neither OpenSSL 3.0.x nor LibCurl 8.18.0 are backwards compatible with Siteminder Policy Server r12.8.8.1 and older.
Upgrading to Libcurl 8.17.0 will still leave the system vulnerable to the following CVE's:
CVE-2026-3784: wrong proxy connection reuse with credentials
CVE-2026-3783: token leak with redirect and netrc
CVE-2026-1965: bad reuse of HTTP Negotiate connection
Upgrade Siteminder r12.8.8.1 or Older to LibCurl 8.17.0
LINUX
1) Download 'libcurl_8.17.0_12.8.x_linux.zip' to the Siteminder Policy Server
2) Decompress 'libcurl_8.17.0_libs.zip'
Contents:
libcurl.so
libcurl.so.4
libcurl.so.4.8.0
3) Stop the Siteminder Policy Server
4) Backup and Delete, or Rename the following files:
/<Install_Dir>/CA/siteminder/lib/libcurl.so.4.8.0
/<Install_Dir>/CA/siteminder/lib/libcurl.so.4
/<Install_Dir>/CA/siteminder/lib/libcurl.so
5) Copy the following files from 'libcurl_8.17.0_12.8.x_linux.zip' into the '/<Install_Dir>/CA/siteminder/lib/' directory.
libcurl.so
libcurl.so.4
libcurl.so.4.8.0
6) Start the Siteminder Policy Server
WINDOWS
1) Download 'libcurl_8.17.0_12.8.x_win64.zip' to the Siteminder Policy Server
2) Decompress 'libcurl_8.17.0_12.8.x_win64.zip'
3) Stop the Siteminder Policy Server
4) Backup and Delete, or Rename the following files:
<Install_Dir>\CA\siteminder\bin\libcurl.dll
5) Copy the following files from 'libcurl_8.17.0_12.8.x_win64' into the '<Install_Dir>\CA\siteminder\bin\' directory.
libcurl.dll
6) Start the Siteminder Policy Server
curl and libcurl vulnerabilities
KB 437711 Vulnerability in Libcurl 8.17.0 and older in the Siteminder Policy Server r12.9 and older
Libcurl 8.17.0 Remediate the following CVE's: