Broadcom Symantec Identity Governance And Administration vulnerabilities
6 known vulnerabilities affecting broadcom/symantec_identity_governance_and_administration.
Total CVEs
6
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
HIGH1MEDIUM5
Vulnerabilities
Page 1 of 1
CVE-2023-23949MEDIUMCVSS 5.4v14.3v14.4.1+1 more2023-01-26
CVE-2023-23949 [MEDIUM] CWE-79 CVE-2023-23949: An authenticated user can supply malicious HTML and JavaScript code that will be executed in the cli
An authenticated user can supply malicious HTML and JavaScript code that will be executed in the client browser.
nvd
CVE-2023-23951MEDIUMCVSS 6.1v14.3v14.4.1+1 more2023-01-26
CVE-2023-23951 [MEDIUM] CWE-79 CVE-2023-23951: Ability to enumerate the Oracle LDAP attributes for the current user by modifying the query used by
Ability to enumerate the Oracle LDAP attributes for the current user by modifying the query used by the application
nvd
CVE-2023-23950MEDIUMCVSS 6.1v14.3v14.4.1+1 more2023-01-26
CVE-2023-23950 [MEDIUM] CWE-79 CVE-2023-23950: User’s supplied input (usually a CRLF sequence) can be used to split a returning response into two r
User’s supplied input (usually a CRLF sequence) can be used to split a returning response into two responses.
nvd
CVE-2022-25628HIGHCVSS 8.8v14.3v14.42022-12-16
CVE-2022-25628 [HIGH] CWE-611 CVE-2022-25628: An authenticated user can perform XML eXternal Entity injection in Management Console in Symantec Id
An authenticated user can perform XML eXternal Entity injection in Management Console in Symantec Identity Manager 14.4
nvd
CVE-2022-25627MEDIUMCVSS 6.7v14.3v14.42022-12-16
CVE-2022-25627 [MEDIUM] CWE-284 CVE-2022-25627: An authenticated administrator who has physical access to the environment can carry out Remote Comma
An authenticated administrator who has physical access to the environment can carry out Remote Command Execution on Management Console in Symantec Identity Manager 14.4
nvd
CVE-2022-25626MEDIUMCVSS 5.3v14.3v14.42022-12-16
CVE-2022-25626 [MEDIUM] CWE-425 CVE-2022-25626: An unauthenticated user can access Identity Manager’s management console specific page URLs. However
An unauthenticated user can access Identity Manager’s management console specific page URLs. However, the system doesn’t allow the user to carry out server side tasks without a valid web session.
nvd