RULE(RULE ID:320624)

Rule General Information
Release Date: 2015-04-28
Rule Name: WEB-OTHER Symantec Encryption Management Server Database Backup Command Injection Vulnerability -2 (CVE-2014-7288)
Severity:
CVE ID:
Rule Protection Details
Description: Symantec PGP Universal Server and Encryption Management Server before 3.3.2 MP7 allow remote authenticated administrators to execute arbitrary shell commands via a crafted command line in a database-backup restore action.
Impact: An attacker can execute arbitrary command via a successful exploit in the context of the vulnerable software.
Affected OS: Solaris, FreeBSD, Windows, Linux, Other Unix, Mac OS
Reference: ExploitDB:35949
SecurityFocusBID:72308
SecurityTrackerID:1031673
Solutions
More advisories have been published on the website, please visit for more suggestions:
http://www.symantec.com/security_response/securityupdates/detail.jsp?fid=security_advisory&