XML Entity Expansion Vulnerability in Symantec Management Console
CVE-2017-6323
8HIGH
What is CVE-2017-6323?
The Symantec Management Console prior to specific updates suffers from a vulnerability involving the processing of XML input with external entity references. An improperly configured XML parser can lead to various issues such as disclosure of sensitive data, potential denial of service, server side request forgery, and unauthorized port scanning from the parser's host. These risks can significantly impact system security and data integrity.
Affected Version(s)
ITMS Prior to ITMS 8.1 RU1, ITMS 8.0_POST_HF6 & ITMS 7.6_POST_HF7
References
CVSS V3.1
Score:
8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Adjacent Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved