RULE(RULE ID:332558)

Rule General Information
Release Date: 2018-06-15
Rule Name: Symantec Workspace Streaming XML-RPC Arbitrary File Upload Vulnerability (CVE-2014-1649)
Severity:
CVE ID:
Rule Protection Details
Description: An arbitrary file upload vulnerability exists in Symantec Workspace. The vulnerability is due to lack of access control validation in the functionality used to process XMLRPC requests. A remote unauthenticated attacker could exploit this vulnerability by a sending specially crafted XML-RPC request to the server.
Impact: Successful exploitation could lead to unauthorized access to sensitive server-side files and functionality. Further exploitation could lead to code execution in the security context of the application through the use of arbitrary file upload.
Affected OS: Windows, Linux, Others
Reference: ExploitDB:33521
SecurityFocusBID:67189
http://www.symantec.com/security_response/securityupdates/detail.jsp?fid=security_advisory&pvid=security_advisory&year=&suid=20140512_00
ZeroDayInitiative:ZDI-14-127
Solutions
The vendor has released upgrade patches to fix vulnerabilities, please visit:
http://www.symantec.com/security_response/securityupdates/detail.jsp?fid=security_advisory&pvid=security_advisory&year=&suid=20140512_00