Known Vulnerabilities for Symantec Identity Manager by Broadcom
Listed below are 3 of the newest known vulnerabilities associated with "Symantec Identity Manager" by "Broadcom".
These CVEs are retrieved based on exact matches on listed software, hardware, and vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed software information are still displayed.
Data on known vulnerable versions is also displayed based on information from known CPEs
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2023-23951 json | Ability to enumerate the Oracle LDAP attributes for the current user by modifying the query used by the application | 6.1 - MEDIUM | 2023-01-26 | 2023-02-07 |
| CVE-2023-23950 json | User’s supplied input (usually a CRLF sequence) can be used to split a returning response into two responses. | 6.1 - MEDIUM | 2023-01-26 | 2023-02-07 |
| CVE-2023-23949 json | An authenticated user can supply malicious HTML and JavaScript code that will be executed in the client browser. | 5.4 - MEDIUM | 2023-01-26 | 2023-02-06 |
Known Affected Configurations (CPE V2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Broadcom | Symantec Identity Manager | 14.4 | |||
| Application | Broadcom | Symantec Identity Manager | 14.3 | |||
| Application | Broadcom | Symantec Identity Manager | 14.2 | |||
| Application | Broadcom | Symantec Identity Manager | 14.1 | |||
| Application | Broadcom | Symantec Identity Manager | 14.0 |