SQL Injection Vulnerability in Symantec LiveUpdate Administrator Management Interface
CVE-2014-1645

Currently unrated

Key Information:

Vendor
Symantec
Vendor
CVE Published:
29 March 2014

Summary

A SQL injection vulnerability exists in the management GUI of Symantec LiveUpdate Administrator (LUA) earlier than version 2.3.2.110. This flaw allows remote attackers to manipulate database queries by injecting arbitrary SQL commands through unspecified vectors, potentially compromising the integrity and security of the system. Organizations using affected versions of LUA should take immediate action to mitigate the risk associated with this vulnerability.

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.