PT-2016-5066 · Symantec · Symantec Workspace Streaming+1
Published
2016-07-12
·
Updated
2017-09-01
·
CVE-2016-2205
CVSS v2.0
6.1
Medium
| Vector | AV:A/AC:L/Au:N/C:C/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Symantec Workspace Streaming (SWS) versions 7.5.x through 7.5 before SP1 HF9
Symantec Workspace Streaming (SWS) version 7.6.0 before 7.6 HF5
Symantec Workspace Virtualization (SWV) versions 7.5.x through 7.5 before SP1 HF9
Symantec Workspace Virtualization (SWV) version 7.6.0 before 7.6 HF5
Description
A directory traversal vulnerability exists in the file-download configuration file in the management console. This issue allows remote authenticated users to read unspecified application files.
Recommendations
For Symantec Workspace Streaming (SWS) versions 7.5.x through 7.5 before SP1 HF9, update to SP1 HF9 or later.
For Symantec Workspace Streaming (SWS) version 7.6.0 before 7.6 HF5, update to 7.6 HF5 or later.
For Symantec Workspace Virtualization (SWV) versions 7.5.x through 7.5 before SP1 HF9, update to SP1 HF9 or later.
For Symantec Workspace Virtualization (SWV) version 7.6.0 before 7.6 HF5, update to 7.6 HF5 or later.
Fix
Path traversal
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Symantec Workspace Streaming
Symantec Workspace Virtualization