2.9
CVE-2013-1615
- EPSS 0.11%
- Veröffentlicht 08.07.2013 17:55:02
- Zuletzt bearbeitet 11.04.2025 00:51:21
- Quelle secure@symantec.com
- CVE-Watchlists
- Unerledigt
The management console (aka Java console) on the Symantec Security Information Manager (SSIM) appliance 4.7.x and 4.8.x before 4.8.1 allows remote attackers to obtain sensitive information via unspecified web-GUI API calls.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Symantec ≫ Security Information Manager Version4.7.0
Symantec ≫ Security Information Manager Version4.7.1
Symantec ≫ Security Information Manager Version4.7.2
Symantec ≫ Security Information Manager Version4.7.3
Symantec ≫ Security Information Manager Version4.7.4
Symantec ≫ Security Information Manager Version4.8.0
Symantec ≫ Security Information Manager Appliance Version-
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.11% | 0.269 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| nvd@nist.gov | 2.9 | 5.5 | 2.9 |
AV:A/AC:M/Au:N/C:P/I:N/A:N
|
CWE-200 Exposure of Sensitive Information to an Unauthorized Actor
The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.