Vulnerabilities (CVE)

Join the Common Vulnerabilities and Exposures (CVE) community and start to get notified about new vulnerabilities.

Filtered by vendor Broadcom Subscribe
Filtered by product Symantec Identity Governance And Administration
Total 6 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2023-23950 1 Broadcom 2 Symantec Identity Governance And Administration, Symantec Identity Manager 2023-02-07 N/A 6.1 MEDIUM
User’s supplied input (usually a CRLF sequence) can be used to split a returning response into two responses.
CVE-2023-23951 1 Broadcom 2 Symantec Identity Governance And Administration, Symantec Identity Manager 2023-02-07 N/A 6.1 MEDIUM
Ability to enumerate the Oracle LDAP attributes for the current user by modifying the query used by the application
CVE-2023-23949 1 Broadcom 2 Symantec Identity Governance And Administration, Symantec Identity Manager 2023-02-06 N/A 5.4 MEDIUM
An authenticated user can supply malicious HTML and JavaScript code that will be executed in the client browser.
CVE-2022-25628 1 Broadcom 1 Symantec Identity Governance And Administration 2022-12-21 N/A 8.8 HIGH
An authenticated user can perform XML eXternal Entity injection in Management Console in Symantec Identity Manager 14.4
CVE-2022-25627 1 Broadcom 1 Symantec Identity Governance And Administration 2022-12-21 N/A 6.7 MEDIUM
An authenticated administrator who has physical access to the environment can carry out Remote Command Execution on Management Console in Symantec Identity Manager 14.4
CVE-2022-25626 1 Broadcom 1 Symantec Identity Governance And Administration 2022-12-21 N/A 5.3 MEDIUM
An unauthenticated user can access Identity Manager’s management console specific page URLs. However, the system doesn’t allow the user to carry out server side tasks without a valid web session.