Description
Prior to ITMS 8.1 RU4, the Symantec Management Console can be susceptible to a directory traversal exploit, which is a type of attack that can occur when there is insufficient security validation / sanitization of user-supplied input file names, such that characters representing "traverse to parent directory" are passed through to the file APIs.
Analysis and contextual insights are available on OpenCVE Cloud.
Remediation
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2017-6979 | Prior to ITMS 8.1 RU4, the Symantec Management Console can be susceptible to a directory traversal exploit, which is a type of attack that can occur when there is insufficient security validation / sanitization of user-supplied input file names, such that characters representing "traverse to parent directory" are passed through to the file APIs. |
References
History
No history.
Status: PUBLISHED
Assigner: symantec
Published:
Updated: 2024-09-17T03:29:03.354Z
Reserved: 2017-10-17T00:00:00.000Z
Link: CVE-2017-15527
No data.
Status : Modified
Published: 2017-11-20T19:29:00.297
Modified: 2026-05-13T00:24:29.033
Link: CVE-2017-15527
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD