CVE-2015-8151: OS Command Injection
Published Feb 18, 2016
·Updated
Symantec Encryption Management Server (SEMS) 3.3.2 before MP12 allows remote authenticated users to execute arbitrary OS commands by leveraging console administrator access.
Affected Software
1 affected component
Symantec Encryption Management Server<=3.3.2
Event History
Feb 18, 2016
CVE Published
via MITRE·10:00 PM
Data Sourced
via MITRE·10:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2015-8151?
CVE-2015-8151 is rated as a high severity vulnerability.
2
How do I fix CVE-2015-8151?
To mitigate CVE-2015-8151, upgrade to Symantec Encryption Management Server version 3.3.2 MP12 or later.
3
What type of users are affected by CVE-2015-8151?
Remote authenticated users with console administrator access are affected by CVE-2015-8151.
4
What vulnerability does CVE-2015-8151 exploit?
CVE-2015-8151 exploits the ability of users to execute arbitrary OS commands.
5
Is CVE-2015-8151 related to Symantec products only?
Yes, CVE-2015-8151 specifically affects the Symantec Encryption Management Server.