CVE-2016-3649: Symantec Endpoint Protection Manager

Medium severity, CVSS 4.3. EPSS: 1.7% chance of exploitation in the next 30 days.

Symantec Endpoint Protection Manager (SEPM) 12.1 before RU6 MP5 allows remote authenticated administrators to enumerate administrator accounts via modified GET requests.

Affected products

  • Symantec Endpoint Protection Manager: up to and including 12.1.6

Published 2016-06-30. Last modified 2026-06-17.