CVE-2003-0106: High severity Symantec Enterprise Firewall vulnerability
Published Mar 27, 2003
·Updated
The HTTP proxy for Symantec Enterprise Firewall (SEF) 7.0 allows proxy users to bypass pattern matching for blocked URLs via requests that are URL-encoded with escapes, Unicode, or UTF-8.
Affected Software
1 affected component
Symantec Enterprise Firewall=7.0
Remediation
Event History
Mar 27, 2003
CVE Published
via MITRE·10:00 AM
Data Sourced
via MITRE·10:00 AM
Description
Apr 2, 2003
Data Sourced
via NVD·05:00 AM
RemedyDescriptionSeverityAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2003-0106?
CVE-2003-0106 is classified as a medium severity vulnerability due to its ability to allow users to bypass URL filtering.
2
How do I fix CVE-2003-0106?
To fix CVE-2003-0106, it is recommended to upgrade to a version of Symantec Enterprise Firewall that addresses this vulnerability.
3
What impact does CVE-2003-0106 have on users?
CVE-2003-0106 allows unauthorized users to access blocked URLs, potentially leading to data exposure or compliance violations.
4
Which versions of Symantec Enterprise Firewall are affected by CVE-2003-0106?
CVE-2003-0106 specifically affects Symantec Enterprise Firewall version 7.0.
5
What type of attacks can CVE-2003-0106 enable?
CVE-2003-0106 can enable attackers to bypass URL filtering mechanisms through URL encoding techniques.