CVE-2016-3651: Symantec Endpoint Protection Manager
High severity, CVSS 8.0. EPSS: 1.8% chance of exploitation in the next 30 days.
Symantec Endpoint Protection Manager (SEPM) 12.1 before RU6 MP5 allows remote authenticated users to discover the PHP JSESSIONID value via unspecified vectors.
Affected products
- Symantec Endpoint Protection Manager: up to and including 12.1.6
Published 2016-06-30. Last modified 2026-06-17.