PT-2016-6357 · Symantec · Symantec Endpoint Protection Manager+2

Hyp3Rlinx

+1

·

Published

2016-06-30

·

Updated

2017-09-03

·

CVE-2016-5304

CVSS v3.1

6.8

Medium

VectorAV:N/AC:L/PR:L/UI:R/S:C/C:N/I:H/A:N
Name of the Vulnerable Software and Affected Versions Symantec Endpoint Protection Manager versions prior to 12.1 RU6 MP5
Description The issue concerns an open redirect vulnerability in a report-routing component. This vulnerability allows remote authenticated users to redirect users to arbitrary web sites, potentially leading to phishing attacks.
Recommendations For versions prior to 12.1 RU6 MP5, update to Symantec Endpoint Protection Manager version 12.1 RU6 MP5 or later to resolve the issue.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2016-5304

Affected Products

Symantec Endpoint Protection Client
Symantec Endpoint Protection Manager
Symantec Endpoint Protection Server