First published: Fri Mar 18 2016(Updated: )
Cross-site request forgery (CSRF) vulnerability in Symantec Endpoint Protection Manager (SEPM) 12.1 before RU6-MP4 allows remote authenticated users to hijack the authentication of administrators for requests that execute arbitrary code by adding lines to a logging script.
Credit: secure@symantec.com
Affected Software | Affected Version | How to fix |
---|---|---|
Symantec Endpoint Protection | <=12.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2015-8152 is classified as a medium severity vulnerability affecting Symantec Endpoint Protection Manager.
To fix CVE-2015-8152, upgrade Symantec Endpoint Protection Manager to version 12.1 RU6-MP4 or later.
CVE-2015-8152 is a Cross-site request forgery (CSRF) vulnerability that allows remote authenticated users to hijack administrator sessions.
Remote authenticated users of Symantec Endpoint Protection Manager prior to version 12.1 RU6-MP4 are impacted by CVE-2015-8152.
An attacker exploiting CVE-2015-8152 can execute arbitrary code by hijacking the authentication of administrators.