First published: Sun Jun 28 2015(Updated: )
Cross-site request forgery (CSRF) vulnerability in the administration console in the Enforce Server in Symantec Data Loss Prevention (DLP) before 12.5.2 allows remote attackers to hijack the authentication of administrators.
Credit: secure@symantec.com
Affected Software | Affected Version | How to fix |
---|---|---|
Symantec Data Loss Prevention (DLP) | <=12.5.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2015-1485 is classified as a critical vulnerability due to its potential for remote exploitation and impact on administrative access.
To remediate CVE-2015-1485, upgrade Symantec Data Loss Prevention to version 12.5.2 or later.
CVE-2015-1485 is a Cross-site Request Forgery (CSRF) vulnerability targeting the administration console.
Administrators using Symantec Data Loss Prevention versions prior to 12.5.2 are at risk from CVE-2015-1485.
An attacker exploiting CVE-2015-1485 could hijack the authentication of DLP administrators, potentially compromising sensitive data.