Symantec Web Gateway Password Change Security Bypass Vulnerability
BID:54430
Info
Symantec Web Gateway Password Change Security Bypass Vulnerability
| Bugtraq ID: | 54430 |
| Class: | Design Error |
| CVE: |
CVE-2012-2977 |
| Remote: | Yes |
| Local: | No |
| Published: | Jul 20 2012 12:00AM |
| Updated: | Aug 22 2012 04:50PM |
| Credit: | An anonymous contributor working through CERT/CC |
| Vulnerable: |
Symantec Web Gateway 5.0.3 Symantec Web Gateway 5.0.1 |
| Not Vulnerable: | |
Discussion
Symantec Web Gateway Password Change Security Bypass Vulnerability
Symantec Web Gateway is prone to a security-bypass vulnerability.
Successful exploits may allow attackers to change another user's password allowing them to gain unauthorized access in the context of the affected user. This may aid in further attacks.
Symantec Web Gateway versions 5.0.x.x are vulnerable.
Symantec Web Gateway is prone to a security-bypass vulnerability.
Successful exploits may allow attackers to change another user's password allowing them to gain unauthorized access in the context of the affected user. This may aid in further attacks.
Symantec Web Gateway versions 5.0.x.x are vulnerable.
Exploit / POC
Symantec Web Gateway Password Change Security Bypass Vulnerability
Attackers can exploit this issue through a browser.
The following exploit is available:
Attackers can exploit this issue through a browser.
The following exploit is available:
Solution / Fix
Symantec Web Gateway Password Change Security Bypass Vulnerability
Solution:
Vendor updates are available. Please see the references for more information.
Solution:
Vendor updates are available. Please see the references for more information.
References
Symantec Web Gateway Password Change Security Bypass Vulnerability
References:
References:
- Symantec Web Gateway (Symantec)