First published: Thu Jan 24 2019(Updated: )
The Symantec Reporter CLI 10.1 prior to 10.1.5.6 and 10.2 prior to 10.2.1.8 is susceptible to an OS command injection vulnerability. An authenticated malicious administrator with Enable mode access can execute arbitrary OS commands with elevated system privileges.
Credit: secure@symantec.com
Affected Software | Affected Version | How to fix |
---|---|---|
Symantec Reporter | >=10.1<10.1.5.6 | |
Symantec Reporter | >=10.2<10.2.1.8 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2018-12237 is considered a high severity vulnerability due to the ability of an authenticated user to execute arbitrary OS commands with elevated privileges.
To fix CVE-2018-12237, update Symantec Reporter to version 10.1.5.6 or 10.2.1.8 or later.
CVE-2018-12237 affects users of Symantec Reporter versions prior to 10.1.5.6 and 10.2.1.8.
CVE-2018-12237 is caused by an OS command injection vulnerability in the Symantec Reporter CLI.
No, CVE-2018-12237 requires authenticated access with Enable mode to exploit the vulnerability.