CVE-2015-1485
Symantec Data Loss Prevention < 12.5.2 - Cross-Site Request Forgery in Administration Console
Title source: llmDescription
Cross-site request forgery (CSRF) vulnerability in the administration console in the Enforce Server in Symantec Data Loss Prevention (DLP) before 12.5.2 allows remote attackers to hijack the authentication of administrators.
References (3)
Core 3
Core References
Third Party Advisory, VDB Entry vdb-entry
x_refsource_sectrack
http://www.securitytracker.com/id/1032710
Third Party Advisory x_refsource_confirm
http://www.symantec.com/security_response/securityupdates/detail.jsp?fid=security_advisory&pvid=security_advisory&year=&suid=20150622_00
Vendor Advisory vdb-entry
x_refsource_bid
http://www.securityfocus.com/bid/75289
Scores
EPSS
0.0016
EPSS Percentile
36.1%
Details
CWE
CWE-352
Status
published
Products (1)
symantec/data_loss_prevention
< 12.5.1
Published
Jun 28, 2015
Tracked Since
Feb 18, 2026