Symantec Security Information Manager Authentication Bypass Vulnerability
BID:18420
CVE-2006-3072 |Info
Symantec Security Information Manager Authentication Bypass Vulnerability
| Bugtraq ID: | 18420 |
| Class: | Design Error |
| CVE: |
CVE-2006-3072 |
| Remote: | No |
| Local: | Yes |
| Published: | Jun 13 2006 12:00AM |
| Updated: | Feb 11 2016 07:31AM |
| Credit: | This issue was announced by Symantec. |
| Vulnerable: |
Symantec Security Information Manager 4.0.2 |
| Not Vulnerable: | |
Discussion
Symantec Security Information Manager Authentication Bypass Vulnerability
Symantec Security Information Manager is prone to a vulnerability that may let malicious users bypass authentication and gain unauthorized access.
This issue is exposed when the application transforms raw rule definitions into Java code. A malicious user with sufficient access to create rules could exploit the issue by creating a specially crafted rule that will let them gain shell access under another user account.
Symantec Security Information Manager is prone to a vulnerability that may let malicious users bypass authentication and gain unauthorized access.
This issue is exposed when the application transforms raw rule definitions into Java code. A malicious user with sufficient access to create rules could exploit the issue by creating a specially crafted rule that will let them gain shell access under another user account.
Exploit / POC
Symantec Security Information Manager Authentication Bypass Vulnerability
Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected]
Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected]
Solution / Fix
Symantec Security Information Manager Authentication Bypass Vulnerability
Solution:
A fix is available.
Symantec Security Information Manager 4.0.2
Solution:
A fix is available.
Symantec Security Information Manager 4.0.2
-
Symantec 4.0.2.29 HOTFIX 1
http://www.symantec.com/techsupp/enterprise
References
Symantec Security Information Manager Authentication Bypass Vulnerability
References:
References: