First published: Wed Jan 21 2015(Updated: )
The ajaxswing webui in the management server in Symantec Critical System Protection (SCSP) 5.2.9 through MP6 and Symantec Data Center Security: Server Advanced (SDCS:SA) 6.0.x through 6.0 MP1 allows remote authenticated users to obtain sensitive server information via unspecified vectors.
Credit: secure@symantec.com
Affected Software | Affected Version | How to fix |
---|---|---|
Broadcom Symantec Critical System Protection | =5.2.9 | |
Broadcom Symantec Data Center Security Server and Agents | =6.0.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2014-9225 is classified as a medium severity vulnerability.
To fix CVE-2014-9225, apply the latest security updates provided by Symantec for SCSP and SDCS:SA.
CVE-2014-9225 affects users of Symantec Critical System Protection 5.2.9 through MP6 and Symantec Data Center Security: Server Advanced 6.0.x through 6.0 MP1.
CVE-2014-9225 is a vulnerability that allows remote authenticated users to access sensitive server information.
Systems running Broadcom Symantec Critical System Protection version 5.2.9 and Broadcom Symantec Data Center Security Server Advanced version 6.0.0 are vulnerable to CVE-2014-9225.