PT-2016-3863 · Symantec · Symantec Endpoint Protection Manager+1
Published
2016-03-18
·
Updated
2016-12-03
·
CVE-2015-8153
CVSS v2.0
8.3
High
| Vector | AV:N/AC:L/Au:M/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
Symantec Endpoint Protection Manager version 12.1 before RU6-MP4
Description
The issue allows remote authenticated users to execute arbitrary SQL commands.
Recommendations
For Symantec Endpoint Protection Manager version 12.1 before RU6-MP4, update to RU6-MP4 or later to resolve the issue.
Fix
SQL injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Symantec Endpoint Protection Manager
Symantec Endpoint Protection Server