CVE-2016-3649
MEDIUMSymantec Endpoint Protection Manager <12.1 - Info Disclosure
Title source: llmDescription
Symantec Endpoint Protection Manager (SEPM) 12.1 before RU6 MP5 allows remote authenticated administrators to enumerate administrator accounts via modified GET requests.
References (3)
Scores
CVSS v3
4.3
EPSS
0.0026
EPSS Percentile
48.5%
Attack Vector
NETWORK
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
Classification
CWE
CWE-200
Status
draft
Affected Products (1)
symantec/endpoint_protection_manager
< 12.1.6
Timeline
Published
Jun 30, 2016
Tracked Since
Feb 18, 2026