CVE-2012-0297: Critical severity symantec web gateway appliance vulnerability
Published May 21, 2012
·Updated
The management GUI in Symantec Web Gateway 5.0.x before 5.0.3 does not properly restrict access to application scripts, which allows remote attackers to execute arbitrary code by (1) injecting crafted data or (2) including crafted data.
Affected Software
3 affected components
Symantec Web Gateway=5.0
Symantec Web Gateway=5.0.1
Symantec Web Gateway=5.0.2
Event History
May 21, 2012
CVE Published
via MITRE·08:00 PM
Data Sourced
via MITRE·08:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2012-0297?
CVE-2012-0297 has a high severity due to its potential to allow remote code execution.
2
How do I fix CVE-2012-0297?
You can fix CVE-2012-0297 by updating Symantec Web Gateway to version 5.0.3 or later.
3
What versions of Symantec Web Gateway are affected by CVE-2012-0297?
CVE-2012-0297 affects Symantec Web Gateway versions 5.0, 5.0.1, and 5.0.2.
4
What type of attack does CVE-2012-0297 allow?
CVE-2012-0297 allows remote attackers to execute arbitrary code through improper access restrictions.
5
Is there a workaround for CVE-2012-0297?
There are no specific workarounds for CVE-2012-0297; applying the appropriate patch is recommended.