Command Injection Vulnerability in Symantec Security Information Manager
CVE-2006-3072
Currently unrated
Summary
The M4 Macro Library in Symantec Security Information Manager prior to the 4.0.2.29 HOTFIX 1 version is susceptible to a command injection vulnerability. Local users can exploit this weakness by crafting malicious 'rule definitions' that lead to the execution of arbitrary commands. This flaw generates unsafe Java code during the M4 transformation process, which can be leveraged to perform unauthorized operations within the system, potentially compromising security.
References
Timeline
Vulnerability published
Vulnerability Reserved