CVE-2014-1649
Published May 16, 2014
Last updated 10 years ago
Overview
- Description
- The server in Symantec Workspace Streaming (SWS) before 7.5.0.749 allows remote attackers to access files and functionality by sending a crafted XMLRPC request over HTTPS.
- Source
- secure@symantec.com
- NVD status
- Modified
Social media
- Hype score
- Not currently trending
Risk scores
CVSS 2.0
- Type
- Primary
- Base score
- 7.9
- Impact score
- 10
- Exploitability score
- 5.5
- Vector string
- AV:A/AC:M/Au:N/C:C/I:C/A:C
Weaknesses
- nvd@nist.gov
- CWE-264
Configurations
[ { "nodes": [ { "negate": false, "cpeMatch": [ { "criteria": "cpe:2.3:a:symantec:workspace_streaming:*:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "18AD51AE-DDE9-4FD3-8C05-39C6EBB4929F", "versionEndIncluding": "7.5.0" }, { "criteria": "cpe:2.3:a:symantec:workspace_streaming:6.1:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "96313018-84AD-4DB4-B5FE-23A49840C0C7" }, { "criteria": "cpe:2.3:a:symantec:workspace_streaming:6.1:sp1:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "376E49E5-5631-4CFE-AF04-ABE615F3F2FA" }, { "criteria": "cpe:2.3:a:symantec:workspace_streaming:6.1:sp2:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "25254E74-3A33-4FAA-914C-1BEE7388F478" }, { "criteria": "cpe:2.3:a:symantec:workspace_streaming:6.1:sp3:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "C14E8F23-7CCA-4371-922A-7994E1D37879" }, { "criteria": "cpe:2.3:a:symantec:workspace_streaming:6.1:sp4:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "0F9C330E-FE35-40BB-ABB9-3A227999C2BD" } ], "operator": "OR" } ] } ]