First published: Thu Feb 18 2016(Updated: )
The LDAP service in Symantec Encryption Management Server (SEMS) 3.3.2 before MP12 allows remote attackers to obtain sensitive information about administrator accounts via a modified request.
Credit: secure@symantec.com
Affected Software | Affected Version | How to fix |
---|---|---|
Symantec Encryption Management Server | <=3.3.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2015-8148 is considered a medium severity vulnerability due to its potential to expose sensitive information about administrator accounts.
To fix CVE-2015-8148, update Symantec Encryption Management Server to version 3.3.2 MP12 or later.
CVE-2015-8148 is an information disclosure vulnerability affecting the LDAP service in Symantec Encryption Management Server.
Yes, CVE-2015-8148 can be exploited remotely by attackers who can send modified requests to the LDAP service.
CVE-2015-8148 affects Symantec Encryption Management Server versions up to and including 3.3.2 MP11.