Last Modified: Sep 13, 2023
Known Affected Versions:
10.2.4, 11.6.0, 11.6.1, 11.6.2, 11.6.3, 188.8.131.52, 184.108.40.206, 220.127.116.11, 18.104.22.168, 11.6.4, 11.6.5, 22.214.171.124, 126.96.36.199, 188.8.131.52
Opened: Apr 30, 2015 Severity: 3-Major Related Article:
Related Article: K16552
10.x WAM policy editor allows the input of special characters on value fields, for example, the accented 'e' character.
WAM does not handle special character matching. For example, WAM does not decode the URI sent by the browser from 'r%C3%A9sum%C3%A9' to the accented word resume).
Using special (non-ASCII) characters.
Do not input special characters in the value text field. Always use the UTF-8 encoding as browsers do (% and hexadecimal). For example, in the value text field, input 'r%C3%A9sum%C3%A9' for the accented word 'resume'.