← Back

Symantec Identity Governance And Administration

symantec_identity_governance_and_administration

Vendor: Broadcom • 6 CVEs

CVEs (6)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Broadcom
2Symantec Identity Governance And Administration
Symantec Identity Manager
Jun 17, 2026
Jan 26, 2023
N/A· v4
6.1 MEDIUM· v3
N/A· v2
Ability to enumerate the Oracle LDAP attributes for the current user by modifying the query used by the application
1Broadcom
2Symantec Identity Governance And Administration
Symantec Identity Manager
Jun 17, 2026
Jan 26, 2023
N/A· v4
6.1 MEDIUM· v3
N/A· v2
User’s supplied input (usually a CRLF sequence) can be used to split a returning response into two responses.
1Broadcom
2Symantec Identity Governance And Administration
Symantec Identity Manager
Jun 17, 2026
Jan 26, 2023
N/A· v4
5.4 MEDIUM· v3
N/A· v2
An authenticated user can supply malicious HTML and JavaScript code that will be executed in the client browser.
1Broadcom
1Symantec Identity Governance And Administration
Jun 17, 2026
Dec 16, 2022
N/A· v4
8.8 HIGH· v3
N/A· v2
An authenticated user can perform XML eXternal Entity injection in Management Console in Symantec Identity Manager 14.4
1Broadcom
1Symantec Identity Governance And Administration
Jun 17, 2026
Dec 16, 2022
N/A· v4
6.7 MEDIUM· v3
N/A· v2
An authenticated administrator who has physical access to the environment can carry out Remote Command Execution on Management Console in Symantec Identity Manager 14.4
1Broadcom
1Symantec Identity Governance And Administration
Jun 17, 2026
Dec 16, 2022
N/A· v4
5.3 MEDIUM· v3
N/A· v2
An unauthenticated user can access Identity Manager’s management console specific page URLs. However, the system doesn’t allow the user to carry out server side tasks without a valid web session.