Vulnerabilities > Symantec > Data Loss Prevention > Medium

DATE CVE VULNERABILITY TITLE RISK
2015-06-28 CVE-2015-1485 Cross-Site Request Forgery (CSRF) vulnerability in Symantec Data Loss Prevention
Cross-site request forgery (CSRF) vulnerability in the administration console in the Enforce Server in Symantec Data Loss Prevention (DLP) before 12.5.2 allows remote attackers to hijack the authentication of administrators.
network
symantec CWE-352
6.8
2015-06-28 CVE-2014-9230 Cross-site Scripting vulnerability in Symantec Data Loss Prevention
Cross-site scripting (XSS) vulnerability in the administration console in the Enforce Server in Symantec Data Loss Prevention (DLP) before 12.5.2 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
network
symantec CWE-79
4.3