CVE-2016-3652: XSS
Published Jun 30, 2016
·Updated
Multiple cross-site scripting (XSS) vulnerabilities in management scripts in Symantec Endpoint Protection Manager (SEPM) 12.1 before RU6 MP5 allow remote authenticated users to inject arbitrary web script or HTML via unspecified vectors.
Affected Software
1 affected component
Symantec Endpoint Protection Manager<=12.1.6
Event History
Jun 30, 2016
CVE Published
via MITRE·11:00 PM
Data Sourced
via MITRE·11:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2016-3652?
CVE-2016-3652 is classified as a medium severity vulnerability.
2
How do I fix CVE-2016-3652?
To mitigate CVE-2016-3652, upgrade Symantec Endpoint Protection Manager to version 12.1.6 RU6 MP5 or later.
3
Who is affected by CVE-2016-3652?
CVE-2016-3652 affects remote authenticated users of Symantec Endpoint Protection Manager versions prior to 12.1.6 RU6 MP5.
4
What types of attacks can be executed due to CVE-2016-3652?
CVE-2016-3652 allows attackers to perform cross-site scripting (XSS) attacks through management scripts.
5
When was CVE-2016-3652 discovered?
CVE-2016-3652 was publicly disclosed in 2016.