CVE-2015-8148: Infoleak
The LDAP service in Symantec Encryption Management Server (SEMS) 3.3.2 before MP12 allows remote attackers to obtain sensitive information about administrator accounts via a modified request.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2015-8148?
CVE-2015-8148 is considered a medium severity vulnerability due to its potential to expose sensitive information about administrator accounts.
How do I fix CVE-2015-8148?
To fix CVE-2015-8148, update Symantec Encryption Management Server to version 3.3.2 MP12 or later.
What type of vulnerability is CVE-2015-8148?
CVE-2015-8148 is an information disclosure vulnerability affecting the LDAP service in Symantec Encryption Management Server.
Can CVE-2015-8148 be exploited remotely?
Yes, CVE-2015-8148 can be exploited remotely by attackers who can send modified requests to the LDAP service.
What software versions are affected by CVE-2015-8148?
CVE-2015-8148 affects Symantec Encryption Management Server versions up to and including 3.3.2 MP11.