The Symantec Messaging Gateway product prior to 10.6.6 may be susceptible to a XML external entity (XXE) exploit, which is a type of issue where XML input containing a reference to an external entity is processed by a weakly configured XML parser. The attack uses file URI schemes or relative paths in the system identifier to access files that should not normally be accessible.
2018-09-19T15:29:19.217
2024-11-21T03:44:50.910
Modified
CVSSv3.0: 8.8 (HIGH)
AV:A/AC:L/Au:N/C:P/I:P/A:P
6.5
6.4
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | symantec | messaging_gateway | < 10.6.6 | Yes |