Symantec Endpoint Protection Manager/Client SQL Injection Vulnerability
Symantec Endpoint Protection Manager/Client SQL Injection Vulnerability
Release date:
Updated on:
Affected Systems:
Symantec Endpoint Protection Manager < 12.1.6
Description:
Bugtraq id: 75204
CVE (CAN) ID: CVE-2014-9229
Symantec Endpoint Protection (SEP) is a new generation of anti-virus and firewall products developed by Symantec Corporation.
Symantec Endpoint Protection (SEP) earlier than 12.1.6 has the SQL injection vulnerability, which allows attackers to control applications, access or modify data.
<* Source: Jan Kadijk
Link: https://www.symantec.com/security_response/securityupdates/detail.jsp? Fid = security_advisory & pvid = sec
*>
Suggestion:
Vendor patch:
Symantec
--------
Symantec has released a Security Bulletin (SYM15-005) and patches for this:
SYM15-005: Security Advisories Relating to Symantec Products-Symantec Endpoint Protection Manager and Client Issues SYM15-005
Link: https://www.symantec.com/security_response/securityupdates/detail.jsp? Fid = security_advisory & pvid = sec
This article permanently updates the link address: