CVE-2019-12753

MEDIUM

Symantec Reporter 10.3-10.3.2.5 - Authenticated Information Disclosure

Title source: llm
STIX 2.1

Description

An information disclosure vulnerability in Symantec Reporter web UI 10.3 prior to 10.3.2.5 allows a malicious authenticated administrator user to obtain passwords for external SMTP, FTP, FTPS, LDAP, and Cloud Log Download servers that they might not otherwise be authorized to access. The malicious administrator user can also obtain the passwords of other Reporter web UI users.

References (1)

Core 1
Core References
Vendor Advisory x_refsource_confirm
https://support.symantec.com/us/en/article.SYMSA1489.html

Scores

CVSS v3 4.9
EPSS 0.0033
EPSS Percentile 56.2%
Attack Vector NETWORK
CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N

Details

Status published
Products (1)
symantec/reporter 10.3 - 10.3.2.5
Published Aug 30, 2019
Tracked Since Feb 18, 2026