Vulnerabilities > CVE-2014-3437 - Unspecified vulnerability in Symantec Endpoint Protection Manager
Attack vector
UNKNOWN Attack complexity
UNKNOWN Privileges required
UNKNOWN Confidentiality impact
UNKNOWN Integrity impact
UNKNOWN Availability impact
UNKNOWN Summary
The management console in Symantec Endpoint Protection Manager (SEPM) 12.1 before RU5 allows remote attackers to read arbitrary files or send TCP requests to intranet servers via XML data containing an external entity declaration in conjunction with an entity reference, related to an XML External Entity (XXE) issue.
Vulnerable Configurations
Part | Description | Count |
---|---|---|
Application | 28 |
Exploit-Db
description | Symantec Endpoint Protection 12.1.4023.4080 - Multiple Vulnerabilities. CVE-2014-3437,CVE-2014-3438,CVE-2014-3439. Webapps exploit for jsp platform |
id | EDB-ID:35181 |
last seen | 2016-02-04 |
modified | 2014-11-06 |
published | 2014-11-06 |
reporter | SEC Consult |
source | https://www.exploit-db.com/download/35181/ |
title | Symantec Endpoint Protection 12.1.4023.4080 - Multiple Vulnerabilities |
Nessus
NASL family | Windows |
NASL id | SYMANTEC_ENDPOINT_PROT_MGR_SYM14-015.NASL |
description | The version of Symantec Endpoint Protection Manager (SEPM) installed on the remote host is 12.1 prior to 12.1 RU5. It is, therefore, affected by the following vulnerabilities : - An XML external entity (XXE) injection vulnerability due to improper validation of XML external entities. A remote attacker, impersonating the input source of external information or updates, can access restricted data or leverage additional management console functionality using specially crafted XML data. (CVE-2014-3437) - A reflected cross-site scripting vulnerability due to improper validation of user-supplied input to the |
last seen | 2020-06-01 |
modified | 2020-06-02 |
plugin id | 79083 |
published | 2014-11-10 |
reporter | This script is Copyright (C) 2014-2018 Tenable Network Security, Inc. |
source | https://www.tenable.com/plugins/nessus/79083 |
title | Symantec Endpoint Protection Manager < 12.1 RU5 Multiple Vulnerabilities (SYM14-015) |
code |
|
Packetstorm
data source | https://packetstormsecurity.com/files/download/129000/SA-20141106-0.txt |
id | PACKETSTORM:129000 |
last seen | 2016-12-05 |
published | 2014-11-06 |
reporter | S. Viehbock |
source | https://packetstormsecurity.com/files/129000/Symantec-Endpoint-Protection-12.1.4023.4080-XXE-XSS-Arbitrary-File-Write.html |
title | Symantec Endpoint Protection 12.1.4023.4080 XXE / XSS / Arbitrary File Write |
Seebug
bulletinFamily | exploit |
description | No description provided by source. |
id | SSV:87397 |
last seen | 2017-11-19 |
modified | 2014-11-13 |
published | 2014-11-13 |
reporter | Root |
source | https://www.seebug.org/vuldb/ssvid-87397 |
title | Symantec Endpoint Protection 12.1.4023.4080 - Multiple Vulnerabilities |
References
- http://seclists.org/fulldisclosure/2014/Nov/7
- http://seclists.org/fulldisclosure/2014/Nov/7
- http://www.securityfocus.com/archive/1/533918/100/0/threaded
- http://www.securityfocus.com/archive/1/533918/100/0/threaded
- http://www.securityfocus.com/bid/70843
- http://www.securityfocus.com/bid/70843
- http://www.securitytracker.com/id/1031176
- http://www.securitytracker.com/id/1031176
- http://www.symantec.com/security_response/securityupdates/detail.jsp?fid=security_advisory&pvid=security_advisory&year=&suid=20141105_00
- http://www.symantec.com/security_response/securityupdates/detail.jsp?fid=security_advisory&pvid=security_advisory&year=&suid=20141105_00
- https://exchange.xforce.ibmcloud.com/vulnerabilities/98525
- https://exchange.xforce.ibmcloud.com/vulnerabilities/98525