vendor:
SEPM
by:
John Page aka HYP3RLINX
6,8
CVSS
MEDIUM
Multiple Cross Site Scripting (XSS), Cross Site Request Forgeries (CSRF), Open Redirect
79, 352, 601
CWE
Product Name: SEPM
Affected Version From: 12.1
Affected Version To: 12.1
Patch Exists: YES
Related CWE: CVE-2016-3652, CVE-2016-3653, CVE-2016-5304
CPE: a:symantec:symantec_endpoint_protection_manager
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: None
2016
Symantec SEPM Multiple Vulnerabilities
The management console for SEPM contains a number of security vulnerabilities that could be used by a lower-privileged user or by an unauthorized user to elevate privilege or gain access to unauthorized information on the management server. Exploitation attempts of these vulnerabilities requires access to the SEP Management console. XSS can bypass the 'http-only' cookie protection because the SEPM application writes and stores the session ID within various javascript functions used by the application within the DOM thereby exposing them directly to the XSS attack.
Mitigation:
Ensure that all users have the least privilege necessary to perform their job functions. Restrict access to the SEPM management console to only authorized personnel. Ensure that all users are using the latest version of the SEPM software.