4 results (0.008 seconds)

CVSS: 4.3EPSS: 3%CPEs: 7EXPL: 0

Multiple cross-site scripting (XSS) vulnerabilities in the management console (aka Java console) on the Symantec Security Information Manager (SSIM) appliance 4.7.x and 4.8.x before 4.8.1 allow remote attackers to inject arbitrary web script or HTML via unspecified vectors. Múltiples vulnerabilidades de ejecución de secuencias de comandos en sitios cruzados en la consola de gestión de Java (tambíen conocida como Java console) en el componente Symantec Security Information Manager (SSIM) v4.7.x y v4.8.x anteriores a v4.8.1 permite a atacantes remotos ejecutar comandos web o HTML mediante vectores no especificados. • http://www.securityfocus.com/bid/60797 http://www.symantec.com/security_response/securityupdates/detail.jsp?fid=security_advisory&pvid=security_advisory&year=&suid=20130701_00 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •

CVSS: 2.9EPSS: 0%CPEs: 7EXPL: 0

The management console (aka Java console) on the Symantec Security Information Manager (SSIM) appliance 4.7.x and 4.8.x before 4.8.1 allows remote attackers to obtain sensitive information via unspecified web-GUI API calls. La consola de gestión de Java (tambíen conocida como Java console) en el componente Symantec Security Information Manager (SSIM) v4.7.x y v4.8.x anteriores a v4.8.1 permite a atacantes remotos a obtener información sensible a través de llamadas a la API web-GUI no especificadas. • http://www.securityfocus.com/bid/60798 http://www.symantec.com/security_response/securityupdates/detail.jsp?fid=security_advisory&pvid=security_advisory&year=&suid=20130701_00 • CWE-200: Exposure of Sensitive Information to an Unauthorized Actor •

CVSS: 4.7EPSS: 0%CPEs: 7EXPL: 0

SQL injection vulnerability in the management console (aka Java console) on the Symantec Security Information Manager (SSIM) appliance 4.7.x and 4.8.x before 4.8.1 allows remote authenticated users to execute arbitrary SQL commands via unspecified vectors. Vulnerabilidad de inyección SQL en la consola de gestión de Java (tambíen conocida como Java console) en el componente Symantec Security Information Manager (SSIM) v4.7.x y v4.8.x anteriores a v4.8.1 permite a atacantes remotos ejecutar comandos SQL a través de vectores no especificados. • http://www.securityfocus.com/bid/60796 http://www.symantec.com/security_response/securityupdates/detail.jsp?fid=security_advisory&pvid=security_advisory&year=&suid=20130701_00 • CWE-89: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') •

CVSS: 4.6EPSS: 0%CPEs: 30EXPL: 0

M4 Macro Library in Symantec Security Information Manager before 4.0.2.29 HOTFIX 1 allows local users to execute arbitrary commands via crafted "rule definitions", which produces dangerous Java code during M4 transformation. Librería M4 Macro de Symantec Security Information Manager anteriores a 4.0.2.29 HOTFIX 1 permiste a usuarios locales ejecutar comandos arbitrarios a través de "reglas de definición" modificadas, lo que produce código Java peligroso durante la transformación M4. • http://secunia.com/advisories/20647 http://securityresponse.symantec.com/avcenter/security/Content/2006.06.13b.html http://securitytracker.com/id?1016296 http://www.securityfocus.com/bid/18420 http://www.vupen.com/english/advisories/2006/2334 https://exchange.xforce.ibmcloud.com/vulnerabilities/27105 •