Description
|
|
A vulnerability has been identified in Symantec Sygate Management Server (SMS), which could be exploited by remote attackers to bypass security restrictions and gain unauthorized access to a vulnerable system. This flaw is due to an input validation error in the authentication servlet that fails to properly validate certain HTTP requests, which could be exploited by remote unauthenticated attackers to overwrite the password for any SMS account (including the SMS administrator account) and gain unauthorized administrative access to the SMS console where they can disable all agents, or propagate malicious scripts to all managed agents.
|