Vulnerability Name: | CVE-2007-3021 (CCN-34744) | ||||||||
Assigned: | 2007-06-05 | ||||||||
Published: | 2007-06-05 | ||||||||
Updated: | 2017-07-29 | ||||||||
Summary: | Symantec Reporting Server 1.0.197.0, and other versions before 1.0.224.0, as used in Symantec Client Security 3.1 and later, and Symantec AntiVirus Corporate Edition (SAV CE) 10.1 and later, does not initialize a critical variable, which allows attackers to create arbitrary executable files via unknown manipulations of a file that is created during data export. | ||||||||
CVSS v3 Severity: | 5.6 Medium (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L)
| ||||||||
CVSS v2 Severity: | 7.5 High (CVSS v2 Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P) 5.5 Medium (Temporal CVSS v2 Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P/E:U/RL:OF/RC:C)
3.8 Low (CCN Temporal CVSS v2 Vector: AV:N/AC:H/Au:N/C:P/I:P/A:P/E:U/RL:OF/RC:C)
| ||||||||
Vulnerability Type: | CWE-Other | ||||||||
Vulnerability Consequences: | Gain Access | ||||||||
References: | Source: MITRE Type: CNA CVE-2007-3021 Source: OSVDB Type: UNKNOWN 36109 Source: CCN Type: SA25543 Symantec Reporting Server Three Vulnerabilities Source: SECUNIA Type: UNKNOWN 25543 Source: CCN Type: SECTRACK ID: 1018196 Symantec Reporting Server Lets Remote Users Execute Arbitrary Code or Obtain the Administrative Password Source: CCN Type: OSVDB ID: 36109 Symantec Multiple Products Reporting Server Data Export Arbitrary File Creation Source: BID Type: UNKNOWN 24313 Source: CCN Type: BID-24313 Symantec System Center Reporting Server Remote Privilege Escalation Vulnerability Source: SECTRACK Type: UNKNOWN 1018196 Source: CCN Type: SYM07-012 Symantec Reporting Server Elevation of Privilege Source: CONFIRM Type: Patch, Vendor Advisory http://www.symantec.com/avcenter/security/Content/2007.06.05a.html Source: VUPEN Type: UNKNOWN ADV-2007-2074 Source: XF Type: UNKNOWN symantec-reporting-code-execution(34744) Source: XF Type: UNKNOWN symantec-reporting-code-execution(34744) | ||||||||
Vulnerable Configuration: | Configuration 1: Configuration CCN 1: Denotes that component is vulnerable | ||||||||
BACK |