CVE-2015-1488: Infoleak
Published Aug 1, 2015
·Updated
An unspecified action handler in the management console in Symantec Endpoint Protection Manager (SEPM) 12.1 before 12.1-RU6-MP1 allows remote authenticated users to read arbitrary files via unknown vectors.
Affected Software
1 affected component
Symantec Endpoint Protection Manager=12.1.0
Event History
Aug 1, 2015
CVE Published
via MITRE·01:00 AM
Data Sourced
via MITRE·01:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2015-1488?
CVE-2015-1488 is rated as a moderate severity vulnerability due to its potential for unauthorized file access.
2
How do I fix CVE-2015-1488?
To fix CVE-2015-1488, upgrade to Symantec Endpoint Protection Manager version 12.1-RU6-MP1 or later.
3
What type of access does CVE-2015-1488 allow?
CVE-2015-1488 allows remote authenticated users to read arbitrary files on the system.
4
Which versions of Symantec Endpoint Protection are affected by CVE-2015-1488?
CVE-2015-1488 affects Symantec Endpoint Protection Manager 12.1 before version 12.1-RU6-MP1.
5
Is there a known exploit for CVE-2015-1488?
While the exact vectors are unspecified, CVE-2015-1488 is known to be exploitable by authenticated users.