Symantec.Workspace.Streaming.XML-RPC.Arbitrary.File.Upload
Description
This indicates an attack attempt to exploit an Arbitrary File Upload vulnerability in Symantec Workspace Streaming.
The vulnerability is due to insufficient sanitizing of user supplied inputs in the application when handling crafted HTTP requests. A remote attacker can exploit this to gain unauthorized access to sensitive information via a crafted request. Also a remote attacker may be able to execute arbitrary code through exploiting this vulnerability.
Affected Products
Symantec Workspace Streaming 7.5.x and prior
Impact
Information Disclosure: Remote attackers can gain sensitive information from vulnerable systems.
System Compromise: Remote attackers can gain control of vulnerable systems.
Recommended Actions
Refer to the vendor's website for suggested workaround.
http://www.symantec.com/security_response/securityupdates/detail.jsp?fid=security_advisory&pvid=security_advisory&year=&suid=20140512_00
Telemetry
Coverage
IPS (Regular DB) | |
IPS (Extended DB) |