First published: Mon Jul 08 2013(Updated: )
The management console (aka Java console) on the Symantec Security Information Manager (SSIM) appliance 4.7.x and 4.8.x before 4.8.1 allows remote attackers to obtain sensitive information via unspecified web-GUI API calls.
Credit: secure@symantec.com
Affected Software | Affected Version | How to fix |
---|---|---|
Symantec Security Information Manager | =4.7.0 | |
Symantec Security Information Manager | =4.7.1 | |
Symantec Security Information Manager | =4.7.2 | |
Symantec Security Information Manager | =4.7.3 | |
Symantec Security Information Manager | =4.7.4 | |
Symantec Security Information Manager | =4.8.0 | |
Symantec Security Information Manager Appliance |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2013-1615 is classified as a medium severity vulnerability.
To remediate CVE-2013-1615, upgrade the Symantec Security Information Manager appliance to version 4.8.1 or later.
Exploitation of CVE-2013-1615 allows remote attackers to obtain sensitive information through certain web-GUI API calls.
CVE-2013-1615 affects Symantec Security Information Manager versions 4.7.x and 4.8.x prior to 4.8.1.
The impact of CVE-2013-1615 is that it can lead to exposure of sensitive information within the management console.