{"api_version":"1","generated_at":"2026-07-23T02:54:20+00:00","cve":"CVE-2007-3095","urls":{"html":"https://cve.report/CVE-2007-3095","api":"https://cve.report/api/cve/CVE-2007-3095.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2007-3095","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2007-3095"},"summary":{"title":"CVE-2007-3095","description":"Unspecified vulnerability in Symantec Reporting Server 1.0.197.0, and other versions before 1.0.224.0, as used in Symantec Client Security 3.1 and later, and Symantec AntiVirus Corporate Edition (SAV CE) 10.1 and later, allows attackers to \"disable the authentication system\" and bypass authentication via unknown vectors.","state":"PUBLISHED","assigner":"mitre","published_at":"2007-06-06 22:30:00","updated_at":"2026-04-23 00:35:47"},"problem_types":["NVD-CWE-Other","n/a"],"metrics":[{"version":"2.0","source":"nvd@nist.gov","type":"Primary","score":"9","severity":"","vector":"AV:N/AC:L/Au:S/C:C/I:C/A:C","data":{"version":"2.0","vectorString":"AV:N/AC:L/Au:S/C:C/I:C/A:C","baseScore":9,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"SINGLE","confidentialityImpact":"COMPLETE","integrityImpact":"COMPLETE","availabilityImpact":"COMPLETE"}}],"references":[{"url":"http://www.securitytracker.com/id?1018196","name":"http://www.securitytracker.com/id?1018196","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"SecurityTracker.com Archives - Symantec Reporting Server Lets Remote Users Execute Arbitrary Code or Obtain the Administrative Password","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/34895","name":"https://exchange.xforce.ibmcloud.com/vulnerabilities/34895","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"IBM X-Force Exchange","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.symantec.com/avcenter/security/Content/2007.06.05.html","name":"http://www.symantec.com/avcenter/security/Content/2007.06.05.html","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"404 Not Found","mime":"text/html","httpstatus":"404","archivestatus":"200"},{"url":"http://www.securityfocus.com/bid/24325","name":"http://www.securityfocus.com/bid/24325","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Symantec Reporting Server Authentication Bypass Vulnerability","mime":"text/html","httpstatus":"200","archivestatus":"0"},{"url":"http://secunia.com/advisories/25543","name":"http://secunia.com/advisories/25543","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Symantec Reporting Server Three Vulnerabilities - Advisories - Secunia","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.vupen.com/english/advisories/2007/2074","name":"http://www.vupen.com/english/advisories/2007/2074","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Webmail : Solution de messagerie professionnelle - OVHcloud- OVH","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://osvdb.org/36107","name":"http://osvdb.org/36107","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"","mime":"","httpstatus":"-1","archivestatus":"0"},{"url":"https://www.cve.org/CVERecord?id=CVE-2007-3095","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2007-3095","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"n/a","product":"n/a","version":"affected n/a","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2007","cve_id":"3095","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"symantec","cpe5":"client_security","cpe6":"3.1","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2007","cve_id":"3095","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"symantec","cpe5":"client_security","cpe6":"3.1.394","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2007","cve_id":"3095","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"symantec","cpe5":"client_security","cpe6":"3.1.396","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2007","cve_id":"3095","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"symantec","cpe5":"client_security","cpe6":"3.1.400","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2007","cve_id":"3095","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"symantec","cpe5":"client_security","cpe6":"3.1.401","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2007","cve_id":"3095","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"symantec","cpe5":"norton_antivirus","cpe6":"10.0.2.2021","cpe7":"*","cpe8":"corporate","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2007","cve_id":"3095","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"symantec","cpe5":"norton_antivirus","cpe6":"10.1","cpe7":"*","cpe8":"corporate","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2007","cve_id":"3095","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"symantec","cpe5":"norton_antivirus","cpe6":"10.1.396","cpe7":"*","cpe8":"corporate","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2007","cve_id":"3095","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"symantec","cpe5":"norton_antivirus","cpe6":"10.1.400","cpe7":"*","cpe8":"corporate","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2007","cve_id":"3095","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"symantec","cpe5":"norton_antivirus","cpe6":"10.1.401","cpe7":"*","cpe8":"corporate","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2007","cve_id":"3095","vulnerable":"1","versionEndIncluding":"1.0.197.0","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"symantec","cpe5":"reporting_server","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"adp":[{"providerMetadata":{"dateUpdated":"2024-08-07T14:05:29.238Z","orgId":"af854a3a-2127-422b-91ae-364da2661108","shortName":"CVE"},"references":[{"name":"36107","tags":["vdb-entry","x_refsource_OSVDB","x_transferred"],"url":"http://osvdb.org/36107"},{"name":"24325","tags":["vdb-entry","x_refsource_BID","x_transferred"],"url":"http://www.securityfocus.com/bid/24325"},{"name":"symantec-unspecified-authentication-bypass(34895)","tags":["vdb-entry","x_refsource_XF","x_transferred"],"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/34895"},{"tags":["x_refsource_CONFIRM","x_transferred"],"url":"http://www.symantec.com/avcenter/security/Content/2007.06.05.html"},{"name":"1018196","tags":["vdb-entry","x_refsource_SECTRACK","x_transferred"],"url":"http://www.securitytracker.com/id?1018196"},{"name":"ADV-2007-2074","tags":["vdb-entry","x_refsource_VUPEN","x_transferred"],"url":"http://www.vupen.com/english/advisories/2007/2074"},{"name":"25543","tags":["third-party-advisory","x_refsource_SECUNIA","x_transferred"],"url":"http://secunia.com/advisories/25543"}],"title":"CVE Program Container"}],"cna":{"affected":[{"product":"n/a","vendor":"n/a","versions":[{"status":"affected","version":"n/a"}]}],"datePublic":"2007-06-05T00:00:00.000Z","descriptions":[{"lang":"en","value":"Unspecified vulnerability in Symantec Reporting Server 1.0.197.0, and other versions before 1.0.224.0, as used in Symantec Client Security 3.1 and later, and Symantec AntiVirus Corporate Edition (SAV CE) 10.1 and later, allows attackers to \"disable the authentication system\" and bypass authentication via unknown vectors."}],"problemTypes":[{"descriptions":[{"description":"n/a","lang":"en","type":"text"}]}],"providerMetadata":{"dateUpdated":"2017-07-28T12:57:01.000Z","orgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","shortName":"mitre"},"references":[{"name":"36107","tags":["vdb-entry","x_refsource_OSVDB"],"url":"http://osvdb.org/36107"},{"name":"24325","tags":["vdb-entry","x_refsource_BID"],"url":"http://www.securityfocus.com/bid/24325"},{"name":"symantec-unspecified-authentication-bypass(34895)","tags":["vdb-entry","x_refsource_XF"],"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/34895"},{"tags":["x_refsource_CONFIRM"],"url":"http://www.symantec.com/avcenter/security/Content/2007.06.05.html"},{"name":"1018196","tags":["vdb-entry","x_refsource_SECTRACK"],"url":"http://www.securitytracker.com/id?1018196"},{"name":"ADV-2007-2074","tags":["vdb-entry","x_refsource_VUPEN"],"url":"http://www.vupen.com/english/advisories/2007/2074"},{"name":"25543","tags":["third-party-advisory","x_refsource_SECUNIA"],"url":"http://secunia.com/advisories/25543"}],"x_legacyV4Record":{"CVE_data_meta":{"ASSIGNER":"cve@mitre.org","ID":"CVE-2007-3095","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"n/a","version":{"version_data":[{"version_value":"n/a"}]}}]},"vendor_name":"n/a"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"Unspecified vulnerability in Symantec Reporting Server 1.0.197.0, and other versions before 1.0.224.0, as used in Symantec Client Security 3.1 and later, and Symantec AntiVirus Corporate Edition (SAV CE) 10.1 and later, allows attackers to \"disable the authentication system\" and bypass authentication via unknown vectors."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"n/a"}]}]},"references":{"reference_data":[{"name":"36107","refsource":"OSVDB","url":"http://osvdb.org/36107"},{"name":"24325","refsource":"BID","url":"http://www.securityfocus.com/bid/24325"},{"name":"symantec-unspecified-authentication-bypass(34895)","refsource":"XF","url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/34895"},{"name":"http://www.symantec.com/avcenter/security/Content/2007.06.05.html","refsource":"CONFIRM","url":"http://www.symantec.com/avcenter/security/Content/2007.06.05.html"},{"name":"1018196","refsource":"SECTRACK","url":"http://www.securitytracker.com/id?1018196"},{"name":"ADV-2007-2074","refsource":"VUPEN","url":"http://www.vupen.com/english/advisories/2007/2074"},{"name":"25543","refsource":"SECUNIA","url":"http://secunia.com/advisories/25543"}]}}}},"cveMetadata":{"assignerOrgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","assignerShortName":"mitre","cveId":"CVE-2007-3095","datePublished":"2007-06-06T22:00:00.000Z","dateReserved":"2007-06-06T00:00:00.000Z","dateUpdated":"2024-08-07T14:05:29.238Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.1"},"nvd":{"publishedDate":"2007-06-06 22:30:00","lastModifiedDate":"2026-04-23 00:35:47","problem_types":["NVD-CWE-Other","n/a"],"metrics":{"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:L/Au:S/C:C/I:C/A:C","baseScore":9,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"SINGLE","confidentialityImpact":"COMPLETE","integrityImpact":"COMPLETE","availabilityImpact":"COMPLETE"},"baseSeverity":"HIGH","exploitabilityScore":8,"impactScore":10,"acInsufInfo":false,"obtainAllPrivilege":true,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:symantec:client_security:3.1:*:*:*:*:*:*:*","matchCriteriaId":"1D24019B-20F0-4B4D-86A5-9409698E6216"},{"vulnerable":true,"criteria":"cpe:2.3:a:symantec:client_security:3.1.394:*:*:*:*:*:*:*","matchCriteriaId":"D6090F86-0B42-403F-9996-9B7670EBAA5A"},{"vulnerable":true,"criteria":"cpe:2.3:a:symantec:client_security:3.1.396:*:*:*:*:*:*:*","matchCriteriaId":"B3706E76-FC65-467E-8D09-A9EAC32E9BBD"},{"vulnerable":true,"criteria":"cpe:2.3:a:symantec:client_security:3.1.400:*:*:*:*:*:*:*","matchCriteriaId":"BF555313-BB5A-4D8A-A3A1-609ABC39F6FE"},{"vulnerable":true,"criteria":"cpe:2.3:a:symantec:client_security:3.1.401:*:*:*:*:*:*:*","matchCriteriaId":"BC74372F-329A-4597-810B-88B865771C9D"},{"vulnerable":true,"criteria":"cpe:2.3:a:symantec:norton_antivirus:10.0.2.2021:*:corporate:*:*:*:*:*","matchCriteriaId":"4D3CBEF5-25C6-41E8-97A3-2AA43134E619"},{"vulnerable":true,"criteria":"cpe:2.3:a:symantec:norton_antivirus:10.1:*:corporate:*:*:*:*:*","matchCriteriaId":"81AE594C-41ED-4FE8-839D-B604AE8DC901"},{"vulnerable":true,"criteria":"cpe:2.3:a:symantec:norton_antivirus:10.1.396:*:corporate:*:*:*:*:*","matchCriteriaId":"4AB33BC0-813C-4944-9835-A1F62614CC97"},{"vulnerable":true,"criteria":"cpe:2.3:a:symantec:norton_antivirus:10.1.400:*:corporate:*:*:*:*:*","matchCriteriaId":"423C4F6C-4D87-4604-9122-02E2F06FAFB7"},{"vulnerable":true,"criteria":"cpe:2.3:a:symantec:norton_antivirus:10.1.401:*:corporate:*:*:*:*:*","matchCriteriaId":"60BBE26A-E648-440F-9F08-AA7DD62D6C11"},{"vulnerable":true,"criteria":"cpe:2.3:a:symantec:reporting_server:*:*:*:*:*:*:*:*","versionEndIncluding":"1.0.197.0","matchCriteriaId":"953B6B3E-C3B9-40E6-95E6-911FFEA9A184"}]}]}]},"legacy_mitre":{"record":{"CveYear":"2007","CveId":"3095","Ordinal":"1","Title":"CVE-2007-3095","CVE":"CVE-2007-3095","Year":"2007"},"notes":[{"CveYear":"2007","CveId":"3095","Ordinal":"1","NoteData":"Unspecified vulnerability in Symantec Reporting Server 1.0.197.0, and other versions before 1.0.224.0, as used in Symantec Client Security 3.1 and later, and Symantec AntiVirus Corporate Edition (SAV CE) 10.1 and later, allows attackers to \"disable the authentication system\" and bypass authentication via unknown vectors.","Type":"Description","Title":"CVE-2007-3095"},{"CveYear":"2007","CveId":"3095","Ordinal":"2","NoteData":"2007-06-06","Type":"Other","Title":"Published"},{"CveYear":"2007","CveId":"3095","Ordinal":"3","NoteData":"2017-07-28","Type":"Other","Title":"Modified"}]}}}