CVE-2014-9224
Symantec Data Center Security - Multiple Vulnerabilities
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
2Exploited in Wild
-Decision
Descriptions
Cross-site scripting (XSS) vulnerability in the ajaxswing webui in the Management Console server in the management server in Symantec Critical System Protection (SCSP) 5.2.9 through MP6 and Symantec Data Center Security: Server Advanced (SDCS:SA) 6.0.x through 6.0 MP1 allows remote authenticated users to inject arbitrary web script or HTML via unspecified vectors.
Vulnerabilidad XSS en la WebUI ajaxswing en el servidor Management Console en la administración del servidor en Symantec Critical System Protection (SCSP) 5.2.9 a través de MP6 y Symantec Data Center Security: Server Advanced (SDCS:SA) 6.0.x a través 6.0 MP1 permite a usuarios remotos autenticados inyectar secuencias de comandos web o HTML arbitrarios a través de vectores no especificados.
Symantec Data Center Security: Server Advanced (SDCS:SA) and Symantec Critical System Protection (SCSP) suffer from cross site scripting, remote SQL injection, information disclosure, and policy bypass vulnerabilities.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2014-12-03 CVE Reserved
- 2015-01-21 CVE Published
- 2015-01-22 First Exploit
- 2024-08-06 CVE Updated
- 2025-04-12 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
CWE
- CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CAPEC
References (7)
URL | Tag | Source |
---|---|---|
http://packetstormsecurity.com/files/130060/Symantec-SDCS-SA-SCSP-XSS-Bypass-SQL-Injection-Disclosure.html | X_refsource_misc |
|
http://seclists.org/fulldisclosure/2015/Jan/91 | Mailing List |
|
http://www.securityfocus.com/archive/1/534527/100/0/threaded | Mailing List | |
http://www.securityfocus.com/bid/72093 | Vdb Entry |
URL | Date | SRC |
---|---|---|
https://packetstorm.news/files/id/130060 | 2015-01-22 | |
https://www.exploit-db.com/exploits/35915 | 2015-01-26 |
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Broadcom Search vendor "Broadcom" | Symantec Critical System Protection Search vendor "Broadcom" for product "Symantec Critical System Protection" | 5.2.9 Search vendor "Broadcom" for product "Symantec Critical System Protection" and version "5.2.9" | - |
Affected
| ||||||
Symantec Search vendor "Symantec" | Data Center Security Search vendor "Symantec" for product "Data Center Security" | 6.0.0 Search vendor "Symantec" for product "Data Center Security" and version "6.0.0" | server_advanced |
Affected
|