CVE Database
/

CVE-2018-12243

Back to search

CVE-2018-12243

Published: Sep 19, 2018

Modified: Sep 16, 2024

PUBLISHED

Description

The Symantec Messaging Gateway product prior to 10.6.6 may be susceptible to a XML external entity (XXE) exploit, which is a type of issue where XML input containing a reference to an external entity is processed by a weakly configured XML parser. The attack uses file URI schemes or relative paths in the system identifier to access files that should not normally be accessible.

VendorProductVersions

Symantec Corporation

Symantec Messaging Gateway

affected
Prior to 10.6.6

References

105330
vdb-entry
x_refsource_BID

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now