Symantec IM Manager Administrator Console Code Injection (CVE-2011-0554)
| Check Point Reference: | CPAI-2011-587 | |
| Date Published: | ||
| Severity: | ||
| Source: | ||
| Industry Reference(s): | CVE-2011-0554 | |
| Protection Provided by: |
Security Gateway
|
|
| Who is Vulnerable? Symantec IM Manager prior to 8.4.18 | ||
| Vulnerability Description A remote code injection vulnerability has been reported in Symantec IM Manager Administrator console. |
||
|
Vulnerability Details The vulnerability is due to an input validation error in the Symantec IM Manager Administrator console. A remote attacker may exploit this vulnerability by enticing a target user to open a specially crafted web page. Successful exploitation will allow an attacker to execute arbitrary code on the server, in the security context of the running service. |
Protection Overview
This protection will detect and block attempts to exploit this vulnerability.
In order for the protection to be activated, update your product to the latest update. For information on how to update , go to SBP-2006-05, Protection tab and select the version of your choice.
To configure the defense, select your product from the list below and follow the related protection steps.