First published: Sun Oct 02 2011(Updated: )
Multiple cross-site scripting (XSS) vulnerabilities in the management console in Symantec IM Manager before 8.4.18 allow remote attackers to inject arbitrary web script or HTML via the (1) refreshRateSetting parameter to IMManager/Admin/IMAdminSystemDashboard.asp, the (2) nav or (3) menuitem parameter to IMManager/Admin/IMAdminTOC_simple.asp, or the (4) action parameter to IMManager/Admin/IMAdminEdituser.asp.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Broadcom Symantec Identity Manager | =8.4.2 | |
Broadcom Symantec Identity Manager | =8.4.8 | |
Broadcom Symantec Identity Manager | =7.5 | |
Broadcom Symantec Identity Manager | =8.4.15 | |
Broadcom Symantec Identity Manager | <=8.4.17 | |
Broadcom Symantec Identity Manager | =8.4.1 | |
Broadcom Symantec Identity Manager | =7.0 | |
Broadcom Symantec Identity Manager | =8.4.9 | |
Broadcom Symantec Identity Manager | =8.4.7 | |
Broadcom Symantec Identity Manager | =8.4.11 | |
Broadcom Symantec Identity Manager | =6.0 | |
Broadcom Symantec Identity Manager | =8.4.12 | |
Broadcom Symantec Identity Manager | =6.5 | |
Broadcom Symantec Identity Manager | =8.4.16 | |
Broadcom Symantec Identity Manager | =8.3 | |
Broadcom Symantec Identity Manager | =8.4.13 | |
Broadcom Symantec Identity Manager | =8.4.5 | |
Broadcom Symantec Identity Manager | =8.4.0 | |
Broadcom Symantec Identity Manager | =8.4.10 | |
Broadcom Symantec Identity Manager | =8.4.6 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2011-0552 is classified as a medium severity vulnerability.
To fix CVE-2011-0552, upgrade Symantec IM Manager to version 8.4.18 or later.
CVE-2011-0552 allows attackers to execute cross-site scripting (XSS) attacks on the management console.
CVE-2011-0552 affects Symantec IM Manager versions up to 8.4.17 and versions 7.0, 7.5, and 8.4.x.
Yes, CVE-2011-0552 requires remote attackers to access the management console to exploit the vulnerability.