Symantec identity governance and administration
This hub aggregates every CVE we track for Symantec identity governance and administration, a product in the security products space. Use it to gauge the current risk picture and drill into individual advisories.
7
CVEs tracked
0
Critical
1
High
0
In CISA KEV
Severity distribution
MEDIUM6HIGH1
Monthly trend
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
2024-092026-08
Latest CVEs
The 7 most recently published vulnerabilities affecting Symantec identity governance and administration.
- CVE-2023-23957Open Redirection Vulnerability in Symantec Identity Portal 14.45.4
- CVE-2023-23951Ability to enumerate the Oracle LDAP attributes for the current user by modifying the query used by the application6.1
- CVE-2023-23950User’s supplied input (usually a CRLF sequence) can be used to split a returning response into two responses.6.1
- CVE-2023-23949An authenticated user can supply malicious HTML and JavaScript code that will be executed in the client browser.5.4
- CVE-2022-25627An authenticated administrator who has physical access to the environment can carry out Remote Command Execution on Management Console in Symantec Identity Manager 14.46.7
- CVE-2022-25628An authenticated user can perform XML eXternal Entity injection in Management Console in Symantec Identity Manager 14.48.8
- CVE-2022-25626An unauthenticated user can access Identity Manager’s management console specific page URLs. However, the system doesn’t allow the user to carry out server side tasks without a valid web session.5.3
Product normalization is registry-driven with AI assist and human review. How it works