CVE-2016-5307: Path Traversal
Published Jun 30, 2016
·Updated
Directory traversal vulnerability in Symantec Endpoint Protection Manager (SEPM) 12.1 before RU6 MP5 allows remote authenticated users to read arbitrary files in the web-root directory tree via unspecified vectors.
Affected Software
1 affected component
Symantec Endpoint Protection Manager<=12.1.6
Event History
Jun 30, 2016
CVE Published
via MITRE·11:00 PM
Data Sourced
via MITRE·11:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2016-5307?
CVE-2016-5307 is classified as a medium severity vulnerability due to its potential to allow remote authenticated users to read arbitrary files.
2
How do I fix CVE-2016-5307?
To mitigate CVE-2016-5307, upgrade to Symantec Endpoint Protection Manager version 12.1 RU6 MP5 or later.
3
Who is affected by CVE-2016-5307?
CVE-2016-5307 affects Symantec Endpoint Protection Manager versions prior to RU6 MP5.
4
What type of vulnerability is CVE-2016-5307?
CVE-2016-5307 is a directory traversal vulnerability that can be exploited through specific vectors.
5
Can CVE-2016-5307 be exploited by unauthenticated users?
No, CVE-2016-5307 requires remote authenticated users to exploit the vulnerability.