The Policy Server bundles Libcurl in the binaries. The following versions of Libcurl are shipped with the Policy Server:
Policy Server r12.8.7: LibCurl 7.84.0
Policy Server r12.8.8: LibCurl 8.4.0
Policy Server r12.8.8.1: LibCurl 8.4.0
Policy Server r12.9: LibCurl 8.12.1.0
KB378171 delivered LibCurl 8.10.0
NOTE: This KB only applies to Policy Server r12.8.8.1 and older. For the 12.9 Policy Servers use KB 451429 Vulnerabilities in Libcurl 8.20.0 and older in the SiteMinder r12.9 Policy Server
PRODUCT: Symantec Siteminder
COMPONENT: Policy Server
VERSIONS: r12.8.7; r12.8.8; r12.8.8.1
OPERATING SYSTEM: Any
The following CVE's have been published for LibCurl 7.84.0 - 8.18.0.
Using this KB you can upgrade LibCurl on the r12.8.8.1 and older SiteMinder Policy Server to LibCurl 8.17.0. LibCurl 8.17.0 has been attached to this KB.
NOTE: There are a number of LibCurl vulnerabilities published which LibCurl 8.17.0 does not remediate. Those CVE's are printed in red in the list above.
It is advised that to remediate all LibCurl CVE's you upgrade the SiteMinder Policy Server to r12.9 or higher.
SiteMinder r12.8.8.1 and older along with LibCurl 8.17.0 and older are both built on OpenSSL 1.0.2. SiteMinder r12.9 and higher along with LibCurl 8.18.0 and higher are both built on OpenSSL 3.0.x. Neither OpenSSL 3.0.x nor LibCurl 8.18.0 are backwards compatible with SiteMinder Policy Server r12.8.8.1 and older.
Upgrading to Libcurl 8.17.0 will still leave the system vulnerable to the following CVE's:
Upgrade SiteMinder r12.8.8.1 or Older to LibCurl 8.17.0
LINUX
1) Download 'libcurl_8.17.0_12.8.x_linux.zip' to the SiteMinder Policy Server
2) Decompress 'libcurl_8.17.0_libs.zip'
Contents:
libcurl.so
libcurl.so.4
libcurl.so.4.8.0
3) Stop the SiteMinder Policy Server
4) Backup and Delete, or Rename the following files:
/<Install_Dir>/CA/siteminder/lib/libcurl.so.4.8.0
/<Install_Dir>/CA/siteminder/lib/libcurl.so.4
/<Install_Dir>/CA/siteminder/lib/libcurl.so
5) Copy the following files from 'libcurl_8.17.0_12.8.x_linux.zip' into the '/<Install_Dir>/CA/siteminder/lib/' directory.
libcurl.so
libcurl.so.4
libcurl.so.4.8.0
6) Start the SiteMinder Policy Server
WINDOWS
1) Download 'libcurl_8.17.0_12.8.x_win64.zip' to the SiteMinder Policy Server
2) Decompress 'libcurl_8.17.0_12.8.x_win64.zip'
3) Stop the SiteMinder Policy Server
4) Backup and Delete, or Rename the following files:
<Install_Dir>\CA\siteminder\bin\libcurl.dll
5) Copy the following files from 'libcurl_8.17.0_12.8.x_win64' into the '<Install_Dir>\CA\siteminder\bin\' directory.
libcurl.dll
6) Start the SiteMinder Policy Server
curl and libcurl vulnerabilities
KB 451429 Vulnerabilities in Libcurl 8.20.0 and older in the SiteMinder r12.9 Policy Server
Libcurl 8.20.0 and older is impacted by the following CVE's:
CVE-2026-12064
CVE-2026-11856
CVE-2026-9547
CVE-2026-8932
CVE-2026-8927
CVE-2026-8924
CVE-2026-8458
CVE-2026-8286
CVE-2026-7168
CVE-2026-6429
CVE-2026-6276
CVE-2026-6253
CVE-2026-5773
CVE-2026-5545
CVE-2026-4873
CVE-2026-3784
CVE-2026-3783
CVE-2026-1965
CVE-2025-15224
CVE-2025-15079
CVE-2025-14524
CVE-2025-14017
CVE-2025-10966
CVE-2025-0725
CVE-2025-0167
CVE-2024-11053
CVE-2024-9681
CVE-2024-8096
CVE-2024-7264
CVE-2024-2398
CVE-2023-46219
CVE-2023-46218
CVE-2023-38546
CVE-2023-38545
CVE-2023-38039
CVE-2023-28322
CVE-2023-28321
CVE-2023-28320
CVE-2023-28319
CVE-2023-27538
CVE-2023-27536
CVE-2023-27535
CVE-2023-27534
CVE-2023-27533
CVE-2023-23916
CVE-2023-23915
CVE-2023-23914
CVE-2022-43552
CVE-2022-43551
CVE-2022-42916
CVE-2022-42915
CVE-2022-35260
CVE-2022-32221
CVE-2022-35252