The management console (aka Java console) on the Symantec Security Information Manager (SSIM) appliance 4.7.x and 4.8.x before 4.8.1 allows remote attackers to obtain sensitive information via unspecified web-GUI API calls.
2013-07-08T17:55:02.877
2025-04-11T00:51:21.963
Deferred
CVSSv2: 2.9 (LOW)
AV:A/AC:M/Au:N/C:P/I:N/A:N
5.5
2.9
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | symantec | security_information_manager | 4.7.0 | Yes |
Application | symantec | security_information_manager | 4.7.1 | Yes |
Application | symantec | security_information_manager | 4.7.2 | Yes |
Application | symantec | security_information_manager | 4.7.3 | Yes |
Application | symantec | security_information_manager | 4.7.4 | Yes |
Application | symantec | security_information_manager | 4.8.0 | Yes |
Hardware | symantec | security_information_manager_appliance | - | Yes |