HomeSecurity4 vulnerabilities identified in Symantec Data Center Security

4 vulnerabilities identified in Symantec Data Center Security

A total of four vulnerabilities have been discovered in Symantec Data Center Security: Server Advanced (SDCS:SA). The vulnerabilities allow a potential attacker to bypass the customer's protection policies and gain access to the system and database.

symantec
Security issues include SQL injection,cross-site scripting (XSS), information disclosure, and policy bypass.

Stefan Viehbock, a security researcher at the SEC Consult Vulnerability Lab, discovered the vulnerabilities and reported them to Symantec on October 20, 2014.

According to a post on Thursday, with the SQL injection vulnerability, which it reports as CVE-2014-7289, an attacker could send SQL commands and have them executed due to the lack of validation of improper inputs which allows read/write access to any record available in a database.

During his investigation, Viehbock managed to add a new user with admin privileges to SDCS:SA.

By exploiting the XSS glitch (CVE-2014-9224), the researcher stated that an attacker could steal a user's session, and gain access to the administrator interface without permission.

With the third vulnerability (CVE-2014-9225) an attacker could take advantage of access to an unprotected script (https://:8081/webui/admin/environment.jsp) that contains internal details about requests to the server, such as file paths on the server and version information (OS, Java).

The fourth vulnerability discovered by Viehbock is reported as CVE-2014-9226 and if exploited can bypass pre-selected security protection policies and bypass the SDCS:SA client.

Symantec has already released patches, but only for the SCSP 5.2.9 MP6 and SDCS:SA 6.0 MP1 products.

 

Source: secnews.gr

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

SecNews
SecNewshttps://www.secnews.gr
In a world without fences and walls, who needs Gates and Windows

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS