Information Disclosure in Symantec Reporter Web UI by Symantec
CVE-2019-12753

4.9MEDIUM

Key Information:

Vendor
CVE Published:
30 August 2019

What is CVE-2019-12753?

The vulnerability allows an authenticated administrator within the Symantec Reporter web UI to access sensitive credentials, including those for external SMTP, FTP, FTPS, LDAP, and Cloud Log Download servers. This exposure could facilitate unauthorized access to resources that the administrator may not have given permission to access, as well as security breaches involving credentials from other users of the Reporter web UI. The affected versions include those prior to 10.3.2.5, presenting a significant risk to organizations reliant on Symantec's reporting tools.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.

Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.

Affected Version(s)

Symantec Reporter Reporter 10.3 prior to 10.3.2.5

References

CVSS V3.1

Score:
4.9
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.