CVE Vulnerabilities

CVE-2019-9697

Published: Aug 30, 2019 | Modified: Jul 21, 2021
CVSS 3.x
6.5
MEDIUM
Source:
NVD
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
CVSS 2.x
4 MEDIUM
AV:N/AC:L/Au:S/C:P/I:N/A:N
RedHat/V2
RedHat/V3
Ubuntu

An information disclosure vulnerability in the Management Center (MC) REST API 2.0, 2.1, and 2.2 prior to 2.2.2.1 allows a malicious authenticated user to obtain passwords for external backup and CPL policy import servers that they might not otherwise be authorized to access.

Affected Software

Name Vendor Start Version End Version
Management_center Symantec 2.2 (including) 2.2.2.1 (excluding)
Management_center Symantec 2.0 (including) 2.0 (including)
Management_center Symantec 2.1 (including) 2.1 (including)

References