Lucene search

K
cveMitreCVE-2006-3072
HistoryJun 19, 2006 - 10:02 a.m.

CVE-2006-3072

2006-06-1910:02:00
mitre
web.nvd.nist.gov
33
cve-2006-3072
m4 macro library
symantec security information manager
command execution
security vulnerability

CVSS2

4.6

Attack Vector

LOCAL

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:L/AC:L/Au:N/C:P/I:P/A:P

AI Score

7.7

Confidence

High

EPSS

0.001

Percentile

25.6%

M4 Macro Library in Symantec Security Information Manager before 4.0.2.29 HOTFIX 1 allows local users to execute arbitrary commands via crafted “rule definitions”, which produces dangerous Java code during M4 transformation.

Affected configurations

Nvd
Node
symantecsecurity_information_managerMatch4.0.2
OR
symantecsecurity_information_managerMatch4.0.2.1
OR
symantecsecurity_information_managerMatch4.0.2.2
OR
symantecsecurity_information_managerMatch4.0.2.3
OR
symantecsecurity_information_managerMatch4.0.2.4
OR
symantecsecurity_information_managerMatch4.0.2.5
OR
symantecsecurity_information_managerMatch4.0.2.6
OR
symantecsecurity_information_managerMatch4.0.2.7
OR
symantecsecurity_information_managerMatch4.0.2.8
OR
symantecsecurity_information_managerMatch4.0.2.9
OR
symantecsecurity_information_managerMatch4.0.2.10
OR
symantecsecurity_information_managerMatch4.0.2.11
OR
symantecsecurity_information_managerMatch4.0.2.12
OR
symantecsecurity_information_managerMatch4.0.2.13
OR
symantecsecurity_information_managerMatch4.0.2.14
OR
symantecsecurity_information_managerMatch4.0.2.15
OR
symantecsecurity_information_managerMatch4.0.2.16
OR
symantecsecurity_information_managerMatch4.0.2.17
OR
symantecsecurity_information_managerMatch4.0.2.18
OR
symantecsecurity_information_managerMatch4.0.2.19
OR
symantecsecurity_information_managerMatch4.0.2.20
OR
symantecsecurity_information_managerMatch4.0.2.21
OR
symantecsecurity_information_managerMatch4.0.2.22
OR
symantecsecurity_information_managerMatch4.0.2.23
OR
symantecsecurity_information_managerMatch4.0.2.24
OR
symantecsecurity_information_managerMatch4.0.2.25
OR
symantecsecurity_information_managerMatch4.0.2.26
OR
symantecsecurity_information_managerMatch4.0.2.27
OR
symantecsecurity_information_managerMatch4.0.2.28
OR
symantecsecurity_information_managerMatch4.0.2.29
VendorProductVersionCPE
symantecsecurity_information_manager4.0.2cpe:2.3:a:symantec:security_information_manager:4.0.2:*:*:*:*:*:*:*
symantecsecurity_information_manager4.0.2.1cpe:2.3:a:symantec:security_information_manager:4.0.2.1:*:*:*:*:*:*:*
symantecsecurity_information_manager4.0.2.2cpe:2.3:a:symantec:security_information_manager:4.0.2.2:*:*:*:*:*:*:*
symantecsecurity_information_manager4.0.2.3cpe:2.3:a:symantec:security_information_manager:4.0.2.3:*:*:*:*:*:*:*
symantecsecurity_information_manager4.0.2.4cpe:2.3:a:symantec:security_information_manager:4.0.2.4:*:*:*:*:*:*:*
symantecsecurity_information_manager4.0.2.5cpe:2.3:a:symantec:security_information_manager:4.0.2.5:*:*:*:*:*:*:*
symantecsecurity_information_manager4.0.2.6cpe:2.3:a:symantec:security_information_manager:4.0.2.6:*:*:*:*:*:*:*
symantecsecurity_information_manager4.0.2.7cpe:2.3:a:symantec:security_information_manager:4.0.2.7:*:*:*:*:*:*:*
symantecsecurity_information_manager4.0.2.8cpe:2.3:a:symantec:security_information_manager:4.0.2.8:*:*:*:*:*:*:*
symantecsecurity_information_manager4.0.2.9cpe:2.3:a:symantec:security_information_manager:4.0.2.9:*:*:*:*:*:*:*
Rows per page:
1-10 of 301

CVSS2

4.6

Attack Vector

LOCAL

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:L/AC:L/Au:N/C:P/I:P/A:P

AI Score

7.7

Confidence

High

EPSS

0.001

Percentile

25.6%

Related for CVE-2006-3072