Lumension® Endpoint Intelligence Center

Intelligence Center » Browse All Vulnerabilities » CVE-2012-4347

Overview

Vulnerability Score 5.0 5.0
CVE Id CVE-2012-4347
Last Modified 11 Oct 2013 09:18:21
Published 05 Dec 2012 06:57:14
Confidentiality Impact PARTIAL PARTIAL
Integrity Impact NONE NONE
Availability Impact NONE NONE
Access Vector NETWORK
Access Complexity LOW
Authentication NONE

CVE-2012-4347

Summary

Multiple directory traversal vulnerabilities in the management console in Symantec Messaging Gateway (SMG) 9.5.x allow remote authenticated users to read arbitrary files via a .. (dot dot) in the (1) logFile parameter in a logs action to brightmail/export or (2) localBackupFileSelection parameter in an APPLIANCE restoreSource action to brightmail/admin/restore/download.do.

Vulnerable Systems

Application

  • Symantec Messaging Gateway 9.5

  • Symantec Messaging Gateway 9.5.1

  • Symantec Messaging Gateway 9.5.2

  • Symantec Messaging Gateway 9.5.3

  • Symantec Messaging Gateway 9.5.4


References

BID - 56789

CONFIRM - http://www.symantec.com/security_response/securityupdates/detail.jsp?fid=security_advisory&pvid=security_advisory&year=&suid=20120827_00

CONFIRM - http://www.symantec.com/security_response/securityupdates/detail.jsp?fid=security_advisory&pvid=security_advisory&year=2012&suid=20120827_00


Last Updated: 27 May 2016 11:03:12