CVE-2022-25627: Medium severity broadcom symantec identity governance and administration vulnerability
Published Dec 16, 2022
·Updated
An authenticated administrator who has physical access to the environment can carry out Remote Command Execution on Management Console in Symantec Identity Manager 14.4
Affected Software
2 affected components
Broadcom Symantec Identity Governance And Administration=14.3
Broadcom Symantec Identity Governance And Administration=14.4
Event History
Dec 16, 2022
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
DescriptionWeakness
Data Sourced
via NVD·04:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2022-25627?
CVE-2022-25627 has a high severity rating due to the potential for Remote Command Execution.
2
How do I fix CVE-2022-25627?
To fix CVE-2022-25627, update Symantec Identity Manager to the latest version provided by Broadcom.
3
What versions of Symantec Identity Manager are affected by CVE-2022-25627?
CVE-2022-25627 affects Symantec Identity Manager versions 14.3 and 14.4.
4
Who can exploit the vulnerability in CVE-2022-25627?
An authenticated administrator with physical access can exploit CVE-2022-25627.
5
What are the consequences of CVE-2022-25627?
The consequences of CVE-2022-25627 include unauthorized remote command execution on the Management Console.