Sensitive Information Exposure in Symantec Encryption Management Server
CVE-2015-8148

7.5HIGH

Key Information:

Vendor
Symantec
Vendor
CVE Published:
18 February 2016

Summary

The LDAP service in Symantec Encryption Management Server (SEMS) 3.3.2 prior to MP12 is vulnerable to a remote information disclosure flaw. This vulnerability allows attackers to craft specially modified requests that can reveal sensitive information about administrator accounts, potentially compromising the security posture of the affected systems. Organizations using SEMS should assess their exposure and ensure that appropriate patches are applied to mitigate this risk.

References

CVSS V3.1

Score:
7.5
Severity:
HIGH
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.