CVE-2014-7288: Symantec Encryption Management Server
High severity, CVSS 9.0. EPSS: 8.1% chance of exploitation in the next 30 days.
Symantec PGP Universal Server and Encryption Management Server before 3.3.2 MP7 allow remote authenticated administrators to execute arbitrary shell commands via a crafted command line in a database-backup restore action.
Affected products
- Symantec Encryption Management Server: up to and including 3.3.2
- Symantec Pgp Universal Server: up to and including 3.3.2
Published 2015-02-01. Last modified 2026-06-17.