Vulnerabilities > Symantec > IT Management Suite

DATE CVE VULNERABILITY TITLE RISK
2020-01-08 CVE-2016-6588 Cross-site Scripting vulnerability in Symantec IT Management Suite 8.0
A Cross-Site Scripting (XSS) vulnerability exists in the ITMS workflow process manager console in Symantec IT Management Suite 8.0.
network
low complexity
symantec CWE-79
5.4
2020-01-08 CVE-2016-6590 Improper Privilege Management vulnerability in Symantec products
A privilege escalation vulnerability exists when loading DLLs during boot up and reboot in Symantec IT Management Suite 8.0 prior to 8.0 HF4 and Suite 7.6 prior to 7.6 HF7, Symantec Ghost Solution Suite 3.1 prior to 3.1 MP4, Symantec Endpoint Virtualization 7.x prior to 7.6 HF7, and Symantec Encryption Desktop 10.x prior to 10.4.1, which could let a local malicious user execute arbitrary code.
local
low complexity
symantec CWE-269
7.8
2020-01-08 CVE-2016-6589 Improper Input Validation vulnerability in Symantec IT Management Suite 8.0
A Denial of Service vulnerability exists in the ITMS workflow process manager login window in Symantec IT Management Suite 8.0.
network
low complexity
symantec CWE-20
6.5