CVE-2015-1485: CSRF
Cross-site request forgery (CSRF) vulnerability in the administration console in the Enforce Server in Symantec Data Loss Prevention (DLP) before 12.5.2 allows remote attackers to hijack the authentication of administrators.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2015-1485?
CVE-2015-1485 is classified as a critical vulnerability due to its potential for remote exploitation and impact on administrative access.
How do I fix CVE-2015-1485?
To remediate CVE-2015-1485, upgrade Symantec Data Loss Prevention to version 12.5.2 or later.
What type of vulnerability is CVE-2015-1485?
CVE-2015-1485 is a Cross-site Request Forgery (CSRF) vulnerability targeting the administration console.
Who is affected by CVE-2015-1485?
Administrators using Symantec Data Loss Prevention versions prior to 12.5.2 are at risk from CVE-2015-1485.
What could an attacker do with CVE-2015-1485?
An attacker exploiting CVE-2015-1485 could hijack the authentication of DLP administrators, potentially compromising sensitive data.