Remote Account Enumeration in Symantec Endpoint Protection Manager
CVE-2016-3649
4.3MEDIUM
What is CVE-2016-3649?
The Symantec Endpoint Protection Manager (SEPM) 12.1 prior to RU6 MP5 allows remote authenticated administrators to exploit a flaw that enables them to enumerate existing administrator accounts through manipulated GET requests. This vulnerability can lead to the exposure of sensitive user information and potentially further attacks within the system.