← Back

CVE-2018-12244

nvd nist
Published: Apr 25, 2019Modified: Nov 21, 2024

JSON object

Loading...
6.3
Vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:L
Exploitability: 2.8 / Impact: 3.4
Source: NVD

Description

SEP (Mac client) prior to and including 12.1 RU6 MP9 and prior to 14.2 RU1 may be susceptible to a CSV/DDE injection (also known as formula injection) vulnerability, which is a type of issue whereby an application or website allows untrusted input into CSV files.

Affected (48)

1 product
Endpoint Protection
Configuration A
48 vulnerable
Vulnerable SoftwareAffected Versions
Symantec
Version 11.0
Version 11.0 mr1
Version 11.0 mr2
Version 11.0 mr3
Version 11.0 mr4-mp2
Version 11.0 mr4
Version 11.0 ru5
Version 11.0 ru6-mp1
Version 11.0 ru6-mp2
Version 11.0 ru6-mp3
Version 11.0 ru6
Version 11.0 ru6a
Version 11.0 ru7-mp1
Version 11.0 ru7-mp2
Version 11.0 ru7-mp4
Version 11.0 ru7-mp4a
Version 11.0 ru7
Version 11.0 ry7-mp3
Version 12.1
Version 12.1 ru1-mp1
Version 12.1 ru1
Version 12.1 ru2-mp1
Version 12.1 ru2
Version 12.1 ru3
Version 12.1 ru4-mp1
Version 12.1 ru4-mp1a
Version 12.1 ru4-mp1b
Version 12.1 ru4
Version 12.1 ru4a
Version 12.1 ru5
Version 12.1 ru6-mp10
Version 12.1 ru6-mp1
Version 12.1 ru6-mp2
Version 12.1 ru6-mp3
Version 12.1 ru6-mp4
Version 12.1 ru6-mp5
Version 12.1 ru6-mp6
Version 12.1 ru6-mp7
Version 12.1 ru6-mp8
Version 12.1 ru6
Version 14.0.0 mp2
Version 14.0.1
Version 14.0.1 mp1
Version 14.0.1 mp2
Version 14.2
Version 14.2 mp1
Version 14
Version 14 mp1

References (4)

Source: secure@symantec.com
Vendor Advisory
Source: secure@symantec.com
Third Party AdvisoryVDB Entry
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party AdvisoryVDB Entry

Timeline

No history available yet.