CVE-2014-7289

medium
Published 2015-01-21 · Modified 2026-05-06
CVSS v3
CVSS v2
6.5
VIR risk
6.5

Description

SQL injection vulnerability in the management server in Symantec Critical System Protection (SCSP) 5.2.9 before MP6 and Symantec Data Center Security: Server Advanced (SDCS:SA) 6.0.x before 6.0 MP1 allows remote authenticated users to execute arbitrary SQL commands via a crafted HTTP request.

Predictions

Exploit likelihood
20%
Patch ETA

Heuristic predictions, AS-IS, for prioritization only.

Mitigations

vendor Authored 2026-05-27

Vendor advisory: secure@symantec.com — http://www.symantec.com/security_response/securityupdates/detail.jsp?fid=security_advisory&pvid=security_advisory&year=&suid=20150119_00

Application impact

VendorProductVersionsFixed
vmware broadcomsymantec_critical_system_protection5.2.9
symantecdata_center_security6.0.0

References

CWEs

CWE-89

Verify integrity in audit chain (admin only). AS-IS.