Vulnerability Name: | CVE-2007-3095 (CCN-34895) | ||||||||
Assigned: | 2007-06-05 | ||||||||
Published: | 2007-06-05 | ||||||||
Updated: | 2017-07-29 | ||||||||
Summary: | Unspecified vulnerability in Symantec Reporting Server 1.0.197.0, and other versions before 1.0.224.0, as used in Symantec Client Security 3.1 and later, and Symantec AntiVirus Corporate Edition (SAV CE) 10.1 and later, allows attackers to "disable the authentication system" and bypass authentication via unknown vectors. | ||||||||
CVSS v3 Severity: | 7.3 High (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L)
| ||||||||
CVSS v2 Severity: | 9.0 High (CVSS v2 Vector: AV:N/AC:L/Au:S/C:C/I:C/A:C) 6.7 Medium (Temporal CVSS v2 Vector: AV:N/AC:L/Au:S/C:C/I:C/A:C/E:U/RL:OF/RC:C)
5.5 Medium (CCN Temporal CVSS v2 Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P/E:U/RL:OF/RC:C)
| ||||||||
Vulnerability Type: | CWE-Other | ||||||||
Vulnerability Consequences: | Bypass Security | ||||||||
References: | Source: MITRE Type: CNA CVE-2007-3095 Source: OSVDB Type: UNKNOWN 36107 Source: CCN Type: SA25543 Symantec Reporting Server Three Vulnerabilities Source: SECUNIA Type: UNKNOWN 25543 Source: CCN Type: SECTRACK ID: 1018196 Symantec Reporting Server Lets Remote Users Execute Arbitrary Code or Obtain the Administrative Password Source: CCN Type: OSVDB ID: 36107 Symantec Multiple Products Reporting Server Unspecified Authentication Bypass Source: BID Type: UNKNOWN 24325 Source: CCN Type: BID-24325 Symantec Reporting Server Authentication Bypass Vulnerability Source: SECTRACK Type: UNKNOWN 1018196 Source: CCN Type: SYM07-011 Symantec Reporting Server Password Disclosure Source: CONFIRM Type: UNKNOWN http://www.symantec.com/avcenter/security/Content/2007.06.05.html Source: VUPEN Type: UNKNOWN ADV-2007-2074 Source: XF Type: UNKNOWN symantec-unspecified-authentication-bypass(34895) Source: XF Type: UNKNOWN symantec-unspecified-authentication-bypass(34895) | ||||||||
Vulnerable Configuration: | Configuration 1: Configuration CCN 1: Denotes that component is vulnerable | ||||||||
BACK |