4.3
CVSSv2

CVE-2014-3438

Published: 07/11/2014 Updated: 09/10/2018
CVSS v2 Base Score: 4.3 | Impact Score: 2.9 | Exploitability Score: 8.6
VMScore: 435
Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N

Vulnerability Summary

Multiple cross-site scripting (XSS) vulnerabilities in console interface scripts in Symantec Endpoint Protection Manager (SEPM) 12.1 before RU5 allow remote malicious users to inject arbitrary web script or HTML via unspecified vectors.

Vulnerable Product Search on Vulmon Subscribe to Product

symantec endpoint protection manager 12.1.1

symantec endpoint protection manager 12.1.2

symantec endpoint protection manager 12.1.3

symantec endpoint protection manager

symantec endpoint protection manager 12.1.0

Exploits

SEC Consult Vulnerability Lab Security Advisory < 20141106-0 > ======================================================================= title: XXE & XSS & Arbitrary File Write vulnerabilities product: Symantec Endpoint Protection vulnerable version: 12140234080 fixed version: 1215 (RU 5) ...
Symantec Endpoint Protection version 12140234080 suffers from XXE injection, cross site scripting, and arbitrary file write vulnerabilities ...