CVE-2015-8153: SQL Injection
Published Mar 18, 2016
·Updated
SQL injection vulnerability in Symantec Endpoint Protection Manager (SEPM) 12.1 before RU6-MP4 allows remote authenticated users to execute arbitrary SQL commands via unspecified vectors.
Affected Software
1 affected component
Symantec Endpoint Protection Manager<=12.1
Event History
Mar 18, 2016
CVE Published
via MITRE·02:00 PM
Data Sourced
via MITRE·02:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2015-8153?
The severity of CVE-2015-8153 is categorized as medium due to its potential impact on database integrity.
2
How do I fix CVE-2015-8153?
To fix CVE-2015-8153, update Symantec Endpoint Protection Manager to version 12.1 RU6-MP4 or later.
3
Who is affected by CVE-2015-8153?
CVE-2015-8153 affects remote authenticated users of Symantec Endpoint Protection Manager version 12.1 before RU6-MP4.
4
What kind of attacks can CVE-2015-8153 facilitate?
CVE-2015-8153 can facilitate SQL injection attacks that allow attackers to execute arbitrary SQL commands.
5
Is CVE-2015-8153 easy to exploit?
CVE-2015-8153 can be exploited via unspecified vectors, which may vary in complexity depending on the user's access level.