Netegrity SiteMinder before 4.11 allows remote attackers to bypass its authentication mechanism by appending "$/FILENAME.ext" (where ext is .ccc, .class, or .jpg) to the requested URL.Referenceshttp://www.atstake.com/research/advisories/2000/a091100-1.txthttps://exchange.xforce.ibmcloud.com/vulnerabilities/5230http://www.securityfocus.com/bid/1681