Skip to main content

Symantec Security Information Manager Console Multiple Vulnerabilities

Last Update Date: 3 Jul 2013 12:39 Release Date: 3 Jul 2013 3367 Views

RISK: Medium Risk

TYPE: Security software and application - Security Software & Appliance

TYPE: Security Software & Appliance

Multiple vulnerabilities have been identified in Symantec Security Information Manager, which can be exploited by malicious users to conduct SQL injection attacks and by malicious people to disclose sensitive information and conduct cross-site scripting attacks.

  1. Certain unspecified input passed to the Java Console is not properly sanitised before being returned to the user. This can be exploited to execute arbitrary HTML and script code in a user's browser session in context of an affected site.
  2. Certain unspecified input is not properly sanitised before being used in SQL queries. This can be exploited to manipulate SQL queries by injecting arbitrary SQL code.
  3. The application console does not properly restrict queries to web-GUI APIs, which an be exploited to disclose certain sensitive information.

Impact

  • Cross-Site Scripting
  • Information Disclosure
  • Data Manipulation

System / Technologies affected

  • versions 4.7.x and 4.8.0

Solutions

Before installation of the software, please visit the software manufacturer web-site for more details.

  • Update to version 4.8.1.

Vulnerability Identifier


Source


Related Link