Description
SQL injection vulnerability in the Management Server in Symantec Embedded Security: Critical System Protection (SES:CSP) 1.0.x before 1.0 MP5, Embedded Security: Critical System Protection for Controllers and Devices (SES:CSP) 6.5.0 before MP1, Critical System Protection (SCSP) before 5.2.9 MP6, Data Center Security: Server Advanced Server (DCS:SA) 6.x before 6.5 MP1 and 6.6 before MP1, and Data Center Security: Server Advanced Server and Agents (DCS:SA) through 6.6 MP1 allows remote authenticated users to execute arbitrary SQL commands via unspecified vectors.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2015-8047 | SQL injection vulnerability in the Management Server in Symantec Embedded Security: Critical System Protection (SES:CSP) 1.0.x before 1.0 MP5, Embedded Security: Critical System Protection for Controllers and Devices (SES:CSP) 6.5.0 before MP1, Critical System Protection (SCSP) before 5.2.9 MP6, Data Center Security: Server Advanced Server (DCS:SA) 6.x before 6.5 MP1 and 6.6 before MP1, and Data Center Security: Server Advanced Server and Agents (DCS:SA) through 6.6 MP1 allows remote authenticated users to execute arbitrary SQL commands via unspecified vectors. |
References
History
No history.
Subscriptions
Broadcom
Subscribe
Symantec Critical System Protection
Subscribe
Symantec Data Center Security Server
Subscribe
Symantec Data Center Security Server And Agents
Subscribe
Symantec Embedded Security Critical System Protection
Subscribe
Symantec Embedded Security Critical System Protection For Controllers And Devices
Subscribe
Status: PUBLISHED
Assigner: symantec
Published:
Updated: 2024-08-06T08:13:31.691Z
Reserved: 2015-11-13T00:00:00.000Z
Link: CVE-2015-8157
No data.
Status : Deferred
Published: 2016-06-08T14:59:00.933
Modified: 2025-04-12T10:46:40.837
Link: CVE-2015-8157
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD