Vulnerabilities > Symantec > Endpoint Protection Manager > High

DATE CVE VULNERABILITY TITLE RISK
2019-11-15 CVE-2019-12759 Unspecified vulnerability in Symantec Endpoint Protection Manager and Mail Security
Symantec Endpoint Protection Manager (SEPM) and Symantec Mail Security for MS Exchange (SMSMSE), prior to versions 14.2 RU2 and 7.5.x respectively, may be susceptible to a privilege escalation vulnerability, which is a type of issue whereby an attacker may attempt to compromise the software application to gain elevated access to resources that are normally protected from an application or user.
local
low complexity
symantec
7.2
2016-03-18 CVE-2015-8153 SQL Injection vulnerability in Symantec Endpoint Protection Manager
SQL injection vulnerability in Symantec Endpoint Protection Manager (SEPM) 12.1 before RU6-MP4 allows remote authenticated users to execute arbitrary SQL commands via unspecified vectors.
network
low complexity
symantec CWE-89
8.3
2016-03-18 CVE-2015-8152 Cross-Site Request Forgery (CSRF) vulnerability in Symantec Endpoint Protection Manager 12.1
Cross-site request forgery (CSRF) vulnerability in Symantec Endpoint Protection Manager (SEPM) 12.1 before RU6-MP4 allows remote authenticated users to hijack the authentication of administrators for requests that execute arbitrary code by adding lines to a logging script.
network
symantec CWE-352
8.5
2015-11-12 CVE-2015-6555 Code Injection vulnerability in Symantec Endpoint Protection Manager
Symantec Endpoint Protection Manager (SEPM) 12.1 before 12.1-RU6-MP3 allows remote attackers to execute arbitrary Java code by connecting to the console Java port.
network
symantec CWE-94
8.5
2015-11-12 CVE-2015-6554 OS Command Injection vulnerability in Symantec Endpoint Protection Manager
Symantec Endpoint Protection Manager (SEPM) 12.1 before 12.1-RU6-MP3 allows remote attackers to execute arbitrary OS commands via crafted data.
network
low complexity
symantec CWE-78
7.5
2015-08-01 CVE-2015-1492 Improper Input Validation vulnerability in Symantec Endpoint Protection Manager 12.1.0
Untrusted search path vulnerability in the client in Symantec Endpoint Protection 12.1 before 12.1-RU6-MP1 allows local users to gain privileges via a Trojan horse DLL in a client install package.
network
symantec CWE-20
8.5
2015-08-01 CVE-2015-1489 Permissions, Privileges, and Access Controls vulnerability in Symantec Endpoint Protection Manager 12.1.0
The management console in Symantec Endpoint Protection Manager (SEPM) 12.1 before 12.1-RU6-MP1 allows remote authenticated users to gain privileges via unspecified vectors.
network
symantec CWE-264
8.5
2015-08-01 CVE-2015-1486 Improper Authentication vulnerability in Symantec Endpoint Protection Manager 12.1.0
The management console in Symantec Endpoint Protection Manager (SEPM) 12.1 before 12.1-RU6-MP1 allows remote attackers to bypass authentication via a crafted password-reset action that triggers a new administrative session.
network
low complexity
symantec CWE-287
7.5
2014-11-07 CVE-2014-3437 XML External Entity Injection vulnerability in Symantec Endpoint Protection Manager
The management console in Symantec Endpoint Protection Manager (SEPM) 12.1 before RU5 allows remote attackers to read arbitrary files or send TCP requests to intranet servers via XML data containing an external entity declaration in conjunction with an entity reference, related to an XML External Entity (XXE) issue.
network
low complexity
symantec
7.5
2014-02-14 CVE-2013-5014 XML External Entity Injection vulnerability in Symantec Endpoint Protection Manager
The management console in Symantec Endpoint Protection Manager (SEPM) 11.0 before 11.0.7405.1424 and 12.1 before 12.1.4023.4080, and Symantec Protection Center Small Business Edition 12.x before 12.1.4023.4080, allows remote attackers to read arbitrary files via XML data containing an external entity declaration in conjunction with an entity reference, related to an XML External Entity (XXE) issue.
network
low complexity
symantec
7.5