Vulnerabilities > Symantec > Workspace Streaming

DATE CVE VULNERABILITY TITLE RISK
2016-07-12 CVE-2016-2206 Permissions, Privileges, and Access Controls vulnerability in Symantec Workspace Streaming and Workspace Virtualization
The management console in Symantec Workspace Streaming (SWS) 7.5.x before 7.5 SP1 HF9 and 7.6.0 before 7.6 HF5 and Symantec Workspace Virtualization (SWV) 7.5.x before 7.5 SP1 HF9 and 7.6.0 before 7.6 HF5 allows remote authenticated users to read arbitrary files by modifying the file-download configuration file.
low complexity
symantec CWE-264
3.3
2016-07-12 CVE-2016-2205 Path Traversal vulnerability in Symantec Workspace Streaming and Workspace Virtualization
Directory traversal vulnerability in the file-download configuration file in the management console in Symantec Workspace Streaming (SWS) 7.5.x before 7.5 SP1 HF9 and 7.6.0 before 7.6 HF5 and Symantec Workspace Virtualization (SWV) 7.5.x before 7.5 SP1 HF9 and 7.6.0 before 7.6 HF5 allows remote authenticated users to read unspecified application files via unknown vectors.
low complexity
symantec CWE-22
6.1
2015-04-22 CVE-2015-1484 Local Privilege Escalation vulnerability in Symantec Workspace Streaming 6.1/7.5
Unquoted Windows search path vulnerability in the agent in Symantec Workspace Streaming (SWS) 6.1 before SP8 MP2 HF7 and 7.5 before SP1 HF4, when AppMgrService.exe is configured as a service, allows local users to gain privileges via a Trojan horse executable file in the %SYSTEMDRIVE% directory, as demonstrated by program.exe.
local
symantec
6.9
2014-05-16 CVE-2014-1649 Permissions, Privileges, and Access Controls vulnerability in Symantec Workspace Streaming 6.1/7.5.0
The server in Symantec Workspace Streaming (SWS) before 7.5.0.749 allows remote attackers to access files and functionality by sending a crafted XMLRPC request over HTTPS.
7.9
2010-06-17 CVE-2008-4389 Improper Authentication vulnerability in Symantec Appstream and Workspace Streaming
Symantec AppStream 5.2.x and Symantec Workspace Streaming (SWS) 6.1.x before 6.1 SP4 do not properly perform authentication, which allows remote Workspace Streaming servers and man-in-the-middle attackers to download arbitrary executable files onto a client system, and execute these files, via unspecified vectors.
network
symantec CWE-287
critical
9.3