Symantec Web Gateway SQL Injection Vulnerability (CVE-2014-1651)
Release date:
Updated on:
Affected Systems:
Symantec Web Gateway <5.2.1
Description:
--------------------------------------------------------------------------------
Bugtraq id: 67754
CVE (CAN) ID: CVE-2014-1651
Symantec Web Gateway provides network content filtering and powerful data leakage protection.
In versions earlier than Symantec Web Gateway 5.2.1, user input is not properly filtered. Multiple SQL injection vulnerabilities exist in the implementation. Attackers can exploit these vulnerabilities to perform unauthorized database operations in the underlying database.
<* Source: Min1214
*>
Suggestion:
--------------------------------------------------------------------------------
Vendor patch:
Symantec
--------
Currently, the vendor does not provide patches or upgrade programs. We recommend that users who use the software follow the vendor's homepage to obtain the latest version:
Http://www.symantec.com/business/security_response/
This article permanently updates the link address: