3 results (0.032 seconds)

CVSS: 4.3EPSS: 3%CPEs: 7EXPL: 0

Multiple cross-site scripting (XSS) vulnerabilities in the management console (aka Java console) on the Symantec Security Information Manager (SSIM) appliance 4.7.x and 4.8.x before 4.8.1 allow remote attackers to inject arbitrary web script or HTML via unspecified vectors. Múltiples vulnerabilidades de ejecución de secuencias de comandos en sitios cruzados en la consola de gestión de Java (tambíen conocida como Java console) en el componente Symantec Security Information Manager (SSIM) v4.7.x y v4.8.x anteriores a v4.8.1 permite a atacantes remotos ejecutar comandos web o HTML mediante vectores no especificados. • http://www.securityfocus.com/bid/60797 http://www.symantec.com/security_response/securityupdates/detail.jsp?fid=security_advisory&pvid=security_advisory&year=&suid=20130701_00 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •

CVSS: 2.9EPSS: 0%CPEs: 7EXPL: 0

The management console (aka Java console) on the Symantec Security Information Manager (SSIM) appliance 4.7.x and 4.8.x before 4.8.1 allows remote attackers to obtain sensitive information via unspecified web-GUI API calls. La consola de gestión de Java (tambíen conocida como Java console) en el componente Symantec Security Information Manager (SSIM) v4.7.x y v4.8.x anteriores a v4.8.1 permite a atacantes remotos a obtener información sensible a través de llamadas a la API web-GUI no especificadas. • http://www.securityfocus.com/bid/60798 http://www.symantec.com/security_response/securityupdates/detail.jsp?fid=security_advisory&pvid=security_advisory&year=&suid=20130701_00 • CWE-200: Exposure of Sensitive Information to an Unauthorized Actor •

CVSS: 4.7EPSS: 0%CPEs: 7EXPL: 0

SQL injection vulnerability in the management console (aka Java console) on the Symantec Security Information Manager (SSIM) appliance 4.7.x and 4.8.x before 4.8.1 allows remote authenticated users to execute arbitrary SQL commands via unspecified vectors. Vulnerabilidad de inyección SQL en la consola de gestión de Java (tambíen conocida como Java console) en el componente Symantec Security Information Manager (SSIM) v4.7.x y v4.8.x anteriores a v4.8.1 permite a atacantes remotos ejecutar comandos SQL a través de vectores no especificados. • http://www.securityfocus.com/bid/60796 http://www.symantec.com/security_response/securityupdates/detail.jsp?fid=security_advisory&pvid=security_advisory&year=&suid=20130701_00 • CWE-89: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') •