First published: Tue Jul 12 2016(Updated: )
Directory traversal vulnerability in the file-download configuration file in the management console in Symantec Workspace Streaming (SWS) 7.5.x before 7.5 SP1 HF9 and 7.6.0 before 7.6 HF5 and Symantec Workspace Virtualization (SWV) 7.5.x before 7.5 SP1 HF9 and 7.6.0 before 7.6 HF5 allows remote authenticated users to read unspecified application files via unknown vectors.
Credit: secure@symantec.com
Affected Software | Affected Version | How to fix |
---|---|---|
Symantec Workspace Streaming | =7.5.0 | |
Symantec Workspace Streaming | =7.5.0-sp1 | |
Symantec Workspace Streaming | =7.6.0 | |
Symantec Workspace Virtualization | =7.5.0 | |
Symantec Workspace Virtualization | =7.5.0-sp1 | |
Symantec Workspace Virtualization | =7.6.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2016-2205 is considered to be a high severity vulnerability due to its potential for remote authentication bypass.
To fix CVE-2016-2205, upgrade to Symantec Workspace Streaming and Workspace Virtualization version 7.5 SP1 HF9 or version 7.6 HF5 or later.
CVE-2016-2205 affects Symantec Workspace Streaming versions 7.5.0 up to 7.5 SP1 HF9 and 7.6.0 up to 7.6 HF5 as well as Symantec Workspace Virtualization with the same version constraints.
Yes, CVE-2016-2205 can be exploited remotely by an attacker without authentication.
CVE-2016-2205 is categorized as a directory traversal vulnerability.