First published: Fri Apr 24 2009(Updated: )
Multiple unspecified vulnerabilities in the Control Center in Symantec Brightmail Gateway Appliance before 8.0.1 allow remote authenticated users to gain privileges, and possibly obtain sensitive information or hijack sessions of arbitrary users, via vectors involving (1) administrative scripts or (2) console functions.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Symantec Brightmail Gateway Appliance | =7.7 | |
Symantec Brightmail Gateway Appliance | =7.5 | |
Symantec Brightmail Gateway Appliance | <=8.0 | |
Symantec Brightmail Gateway Appliance | =7.6 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2009-0064 has a moderate severity rating due to its potential for privilege escalation and session hijacking.
To fix CVE-2009-0064, upgrade to Symantec Brightmail Gateway Appliance version 8.0.1 or later.
CVE-2009-0064 affects Symantec Brightmail Gateway Appliance versions 7.5, 7.6, 7.7, and any version up to 8.0.
Yes, CVE-2009-0064 can be exploited by remote authenticated users.
CVE-2009-0064 includes multiple unspecified vulnerabilities that could allow for privilege escalation and session hijacking.