Lumension® Endpoint Intelligence Center

Intelligence Center » Browse All Vulnerabilities » CVE-2014-7289

Overview

Vulnerability Score 6.5 6.5
CVE Id CVE-2014-7289
Last Modified 22 Jan 2015 08:48:50
Published 21 Jan 2015 10:17:02
Confidentiality Impact PARTIAL PARTIAL
Integrity Impact PARTIAL PARTIAL
Availability Impact PARTIAL PARTIAL
Access Vector NETWORK
Access Complexity LOW
Authentication SINGLE_INSTANCE

CVE-2014-7289

Summary

SQL injection vulnerability in the management server in Symantec Critical System Protection (SCSP) 5.2.9 before MP6 and Symantec Data Center Security: Server Advanced (SDCS:SA) 6.0.x before 6.0 MP1 allows remote authenticated users to execute arbitrary SQL commands via a crafted HTTP request.

Vulnerable Systems

Application

  • Symantec Critical System Protection 5.2.9

  • Symantec Data Center Security 6.0.0


References

CONFIRM - http://www.symantec.com/security_response/securityupdates/detail.jsp?fid=security_advisory&pvid=security_advisory&year=&suid=20150119_00

BID - 72092


Last Updated: 27 May 2016 11:07:35