Lumension® Endpoint Intelligence Center

Intelligence Center » Browse All Vulnerabilities » CVE-2014-9225

Overview

Vulnerability Score 4.0 4.0
CVE Id CVE-2014-9225
Last Modified 22 Jan 2015 10:20:33
Published 21 Jan 2015 10:17:06
Confidentiality Impact PARTIAL PARTIAL
Integrity Impact NONE NONE
Availability Impact NONE NONE
Access Vector NETWORK
Access Complexity LOW
Authentication SINGLE_INSTANCE

CVE-2014-9225

Summary

The ajaxswing webui in the management server in Symantec Critical System Protection (SCSP) 5.2.9 through MP6 and Symantec Data Center Security: Server Advanced (SDCS:SA) 6.0.x through 6.0 MP1 allows remote authenticated users to obtain sensitive server information via unspecified vectors.

Vulnerable Systems

Application

  • Symantec Critical System Protection 5.2.9

  • Symantec Data Center Security 6.0.0


References

CONFIRM - http://www.symantec.com/security_response/securityupdates/detail.jsp?fid=security_advisory&pvid=security_advisory&year=&suid=20150119_00

BID - 72094


Last Updated: 27 May 2016 11:07:36