CVE-2017-15527 - CVE House
Back to Database
Status published Medium CVE-2017-15527

Prior to ITMS 8.1 RU4, the Symantec Management Console can...

Vulnerability Description

Prior to ITMS 8.1 RU4, the Symantec Management Console can be susceptible to a directory traversal exploit, which is a type of attack that can occur when there is insufficient security validation / sanitization of user-supplied input file names, such that characters representing "traverse to parent directory" are passed through to the file APIs.

Impact Analysis

Refer to official advisory for detailed impact metrics.

Remediation

Ensure systems are updated to the latest vendor-supplied patch levels.

THREAT MONITOR

Am I Vulnerable?

Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2017-15527

Credits & Attribution

No credits recorded in the NVD database.

Affected Vendor

Symantec Corporation

View all reports →

Affected Software

Symantec Management Console
Vulnerable Versions:
Prior to ITMS 8.1 RU4

Timeline

Official Publish: November 20th, 2017
Last Modified: September 17th, 2024
Added to House: July 20th, 2026

CVSS Vectors

V3: CVSS:3.0/AV:A/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H

Weaknesses (CWE)

No CWE data available

MITRE ATT&CK TTPs

No associated TTPs found for this vulnerability.