CVE-2012-0298: Medium severity symantec web gateway appliance vulnerability
Published May 21, 2012
·Updated
The file-management scripts in the management GUI in Symantec Web Gateway 5.0.x before 5.0.3 allow remote attackers to (1) read or (2) delete arbitrary files via unspecified vectors.
Affected Software
3 affected components
Symantec Web Gateway=5.0
Symantec Web Gateway=5.0.1
Symantec Web Gateway=5.0.2
Event History
May 21, 2012
CVE Published
via MITRE·08:00 PM
Data Sourced
via MITRE·08:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2012-0298?
CVE-2012-0298 has a medium severity rating due to the potential for unauthorized file access and deletion.
2
How do I fix CVE-2012-0298?
To fix CVE-2012-0298, upgrade to Symantec Web Gateway version 5.0.3 or later.
3
What types of attacks are possible with CVE-2012-0298?
CVE-2012-0298 allows remote attackers to read or delete arbitrary files on affected installations.
4
Which versions of Symantec Web Gateway are affected by CVE-2012-0298?
Symantec Web Gateway versions 5.0, 5.0.1, and 5.0.2 are all affected by CVE-2012-0298.
5
What are the potential impacts of CVE-2012-0298?
The potential impacts of CVE-2012-0298 include data loss, system compromise, and unauthorized information disclosure.