CVE-2016-3653: CSRF
Multiple cross-site request forgery (CSRF) vulnerabilities in management scripts in Symantec Endpoint Protection Manager (SEPM) 12.1 before RU6 MP5 allow remote authenticated users to hijack the authentication of arbitrary users.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2016-3653?
CVE-2016-3653 is classified as a medium severity vulnerability that allows remote authenticated users to hijack the authentication of arbitrary users.
How do I fix CVE-2016-3653?
To fix CVE-2016-3653, upgrade to Symantec Endpoint Protection Manager version 12.1 RU6 MP5 or later.
What types of attacks can CVE-2016-3653 enable?
CVE-2016-3653 can enable cross-site request forgery (CSRF) attacks, which can allow an attacker to perform unauthorized actions on behalf of legitimate users.
Who is affected by CVE-2016-3653?
CVE-2016-3653 affects users of Symantec Endpoint Protection Manager version 12.1 before RU6 MP5.
Is CVE-2016-3653 a client-side or server-side vulnerability?
CVE-2016-3653 is a server-side vulnerability affecting the management scripts within the Symantec Endpoint Protection Manager.