CVE-2016-2206
Summary
| CVE | CVE-2016-2206 |
|---|---|
| State | PUBLISHED |
| Assigner | symantec |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2016-07-12 02:00:06 UTC |
| Updated | 2026-05-06 22:30:45 UTC |
| Description | The management console in Symantec Workspace Streaming (SWS) 7.5.x before 7.5 SP1 HF9 and 7.6.0 before 7.6 HF5 and Symantec Workspace Virtualization (SWV) 7.5.x before 7.5 SP1 HF9 and 7.6.0 before 7.6 HF5 allows remote authenticated users to read arbitrary files by modifying the file-download configuration file. |
Risk And Classification
Primary CVSS: v3.0 5.7 MEDIUM from [email protected]
CVSS:3.0/AV:A/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Problem Types: CWE-264 | n/a
| Version | Source | Type | Score | Severity | Vector |
|---|---|---|---|---|---|
| 3.0 | [email protected] | Primary | 5.7 | MEDIUM | CVSS:3.0/AV:A/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N |
| 2.0 | [email protected] | Primary | 3.3 | AV:A/AC:L/Au:N/C:P/I:N/A:N |
CVSS v3.0 Breakdown
Attack Vector
AdjacentAttack Complexity
LowPrivileges Required
LowUser Interaction
NoneScope
UnchangedConfidentiality
HighIntegrity
NoneAvailability
NoneCVSS:3.0/AV:A/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
CVSS v2.0 Breakdown
Access Vector
AdjacentAccess Complexity
LowAuthentication
NoneConfidentiality
PartialIntegrity
NoneAvailability
NoneAV:A/AC:L/Au:N/C:P/I:N/A:N
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Symantec | Workspace Streaming | 7.5.0 | All | All | All |
| Application | Symantec | Workspace Streaming | 7.5.0 | sp1 | All | All |
| Application | Symantec | Workspace Streaming | 7.6.0 | All | All | All |
| Application | Symantec | Workspace Virtualization | 7.5.0 | All | All | All |
| Application | Symantec | Workspace Virtualization | 7.5.0 | sp1 | All | All |
| Application | Symantec | Workspace Virtualization | 7.6.0 | All | All | All |
Vendor Declared Affected Products
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Mutiple Symantec Products CVE-2016-2206 Arbitrary File Read Vulnerability | af854a3a-2127-422b-91ae-364da2661108 | www.securityfocus.com | |
| Symantec Workspace Virtualization Directory Traversal Flaw Lets Remote Authenticated Users View Arbitrary Files - SecurityTracker | af854a3a-2127-422b-91ae-364da2661108 | www.securitytracker.com | |
| Security Advisories Relating to Symantec Products - Symantec Workspace Streaming and Workspace Virtualization Path Traversal and Arbitrary File Read - 2016-07-07T03:00:00 PDT | Symantec | af854a3a-2127-422b-91ae-364da2661108 | www.symantec.com | Vendor Advisory |
| Symantec Workspace Streaming Directory Traversal Flaw Lets Remote Authenticated Users View Arbitrary Files - SecurityTracker | af854a3a-2127-422b-91ae-364da2661108 | www.securitytracker.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.