CVE-2015-8152: CSRF
Cross-site request forgery (CSRF) vulnerability in Symantec Endpoint Protection Manager (SEPM) 12.1 before RU6-MP4 allows remote authenticated users to hijack the authentication of administrators for requests that execute arbitrary code by adding lines to a logging script.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2015-8152?
CVE-2015-8152 is classified as a medium severity vulnerability affecting Symantec Endpoint Protection Manager.
How do I fix CVE-2015-8152?
To fix CVE-2015-8152, upgrade Symantec Endpoint Protection Manager to version 12.1 RU6-MP4 or later.
What type of vulnerability is CVE-2015-8152?
CVE-2015-8152 is a Cross-site request forgery (CSRF) vulnerability that allows remote authenticated users to hijack administrator sessions.
Who is impacted by CVE-2015-8152?
Remote authenticated users of Symantec Endpoint Protection Manager prior to version 12.1 RU6-MP4 are impacted by CVE-2015-8152.
What can an attacker do exploiting CVE-2015-8152?
An attacker exploiting CVE-2015-8152 can execute arbitrary code by hijacking the authentication of administrators.