CVE-2026-6629 flagged on SiteMinder Access Gateway and Sharepoint Servers
search cancel

CVE-2026-6629 flagged on SiteMinder Access Gateway and Sharepoint Servers

book

Article ID: 451465

calendar_today

Updated On:

Products

SITEMINDER CA Single Sign On Secure Proxy Server (SiteMinder) CA Single Sign On Agents (SiteMinder)

Issue/Introduction

A security may flag CVE CVE-2026-6629 for SiteMinder Access Gateway and Agent for Sharepoint Servers.  This is a vulnerability published for Tomcat 9.0.120 and older.

SiteMinder Access Gateway r12.8.7 and higher bundles Apache Tomcat 9.0.x as the application server.  Tomcat versions vary by the Access Gateway release:

r12.8.7:    Apache Tomcat 9.0.65
r12.8.8:    Apache Tomcat 9.0.83
r12.8.8.1  Apache Tomcat 9.0.86

r12.9 ships with Apache Tomcat 9.0.100.0

KB281190 (archived) delivered Tomcat 9.0.86
KB381451 (archived) delivered Tomcat 9.0.96
KB383137 (archived) delivered Tomcat 9.0.97
KB384944 (archived) delivered Tomcat 9.0.98
KB397315 (archived) delivered Tomcat 9.0.104
KB403333 (archived) delivered Tomcat 9.0.106
KB406223 (archived) delivered Tomcat 9.1.107
KB417926 (archived) delivered Tomcat 9.0.110
KB431996 (archived) delivered Tomcat 9.0.115
KB437528 (archived) delivered Tomcat 9.0.117
KB441198 (archived) delivered Tomcat 9.0.118
KB448422 (archived) delivered Tomcat 9.0.120

The SiteMinder Web Agent for Sharepoint 12.8.7 and higher bundles Tomcat 9.0.x as the application server.  Tomcat versions vary by the Web Agent for Sharepoint release:

r12.8.7: Tomcat 9.0.70
r12.8.8: Tomcat 9.0.83

KB406223 (archived) delivered Tomcat 9.0.105
KB417957 (archived) delivered Tomcat 9.0.107
KB417957 (archived) delivered Tomcat 9.0.111
KB433468 (archived) delivered Tomcat 9.0.115
KB437759 (archived) delivered Tomcat 9.1.117
KB442459 (archived) delivered Tomcat 9.1.118
KB448541 (archived) delivered Tomcat 9.1.120

Environment

PRODUCT: SiteMinder

COMPONENT: Access Gateway Server

VERSIONS: 12.8.x; 12.9

OS: Any

COMPONENT: Sharepoint Agent

VERSIONS: 12.8.x

OS: Any

Cause

CVE-2026-66299: DoS in WebSocket chat example 

SEVERITY: Low

DESCRIPTION: The WebSocket chat example provided an unbounded buffer for undelivered messages. A maliciously slow client could cause the buffer to grow continuously, eventually leading to an memory exhaustion and failure of the Tomcat process.

IMPACTS: Tomcat 9.0.89 to 9.0.120
REMEDIATED: Tomcat 9.0.121

NOTE: Users who followed the security guidance to remove the examples web application are not affected.

Resolution

CVE-2026-66299 does not impact any versions of SiteMinder Access Gateway or the Agent for Sharepoint. 

The security notification for CVE-2026-66299 indicates that this vulnerability can be mitigated by doing the following:

Delete any of the following:

<Tomcat_Install_Dir>/webapps/examples/

<Tomcat_Install_Dir>/webapps/examples.war

<Tomcat_Install_Dir>/work/Catalina/localhost/examples/

While SiteMinder bundles an instance of the Apache Tomcat app server with Access Gateway and the Agent for Sharepoint, this is not a full installation.  SiteMinder does not include the 'examples' web application with its installation.  Therefore the Tomcat instance on SiteMinder components is not susceptible to this vulnerability.