Symantec Endpoint Protection Manager CVE-2014-3437 XML External Entity Injection Vulnerability
BID:70843
Info
Symantec Endpoint Protection Manager CVE-2014-3437 XML External Entity Injection Vulnerability
| Bugtraq ID: | 70843 |
| Class: | Failure to Handle Exceptional Conditions |
| CVE: |
CVE-2014-3437 |
| Remote: | Yes |
| Local: | No |
| Published: | Nov 05 2014 12:00AM |
| Updated: | Nov 05 2014 12:00AM |
| Credit: | Stefan Viehböck with SEC Consult Vulnerability Lab |
| Vulnerable: |
Symantec Endpoint Protection Manager 12.1 RU4 Symantec Endpoint Protection Manager 12.1 RU3 Symantec Endpoint Protection Manager 12.1 RU2 Symantec Endpoint Protection Manager 12.1 |
| Not Vulnerable: |
Symantec Endpoint Protection Manager 12.1 RU5 |
Discussion
Symantec Endpoint Protection Manager CVE-2014-3437 XML External Entity Injection Vulnerability
Symantec Endpoint Protection Manager is prone to an XML External Entity injection vulnerability.
Successfully exploiting this issue may allow an attacker to gain unauthorized access; this may aid in further attacks.
Symantec Endpoint Protection Manager is prone to an XML External Entity injection vulnerability.
Successfully exploiting this issue may allow an attacker to gain unauthorized access; this may aid in further attacks.
References
Symantec Endpoint Protection Manager CVE-2014-3437 XML External Entity Injection Vulnerability
References:
References:
- F-Secure Homepage (F-Secure)
- SYM14-015: Symantec Endpoint Protection Manager Multiple Issues (Symantec)