Symantec Endpoint Protection Manager CVE-2013-5014 XML External Entity Injection Vulnerability
BID:65466
Info
Symantec Endpoint Protection Manager CVE-2013-5014 XML External Entity Injection Vulnerability
| Bugtraq ID: | 65466 |
| Class: | Failure to Handle Exceptional Conditions |
| CVE: |
CVE-2013-5014 |
| Remote: | Yes |
| Local: | No |
| Published: | Feb 13 2014 12:00AM |
| Updated: | Feb 26 2014 01:31PM |
| Credit: | SEC Consult |
| Vulnerable: | |
| Not Vulnerable: | |
Discussion
Symantec Endpoint Protection Manager CVE-2013-5014 XML External Entity Injection Vulnerability
Symantec Endpoint Protection Manager is prone to XML External Entity injection vulnerability.
Successfully exploiting this issue may allow an attacker to gain unauthorized access; this may aid in further attacks.
The following versions are vulnerable:
Symantec Endpoint Protection Manager 11.0
Symantec Endpoint Protection Center Small Business Edition 12.0
Symantec Endpoint Protection Manager 12.1
Symantec Endpoint Protection Manager is prone to XML External Entity injection vulnerability.
Successfully exploiting this issue may allow an attacker to gain unauthorized access; this may aid in further attacks.
The following versions are vulnerable:
Symantec Endpoint Protection Manager 11.0
Symantec Endpoint Protection Center Small Business Edition 12.0
Symantec Endpoint Protection Manager 12.1
Exploit / POC
Symantec Endpoint Protection Manager CVE-2013-5014 XML External Entity Injection Vulnerability
The following exploits are available:
The following exploits are available:
Solution / Fix
Symantec Endpoint Protection Manager CVE-2013-5014 XML External Entity Injection Vulnerability
Solution:
Updates are available. Please see the references or vendor advisory for more information.
Solution:
Updates are available. Please see the references or vendor advisory for more information.
References
Symantec Endpoint Protection Manager CVE-2013-5014 XML External Entity Injection Vulnerability
References:
References:
- Symantec Homepage (Symantec Corp.)