CVE-2018-12237: Symantec Reporter
High severity, CVSS 7.2. EPSS: 2.7% chance of exploitation in the next 30 days.
The Symantec Reporter CLI 10.1 prior to 10.1.5.6 and 10.2 prior to 10.2.1.8 is susceptible to an OS command injection vulnerability. An authenticated malicious administrator with Enable mode access can execute arbitrary OS commands with elevated system privileges.
Affected products
- Symantec Reporter: from 10.1, before 10.1.5.6 (fixed in 10.1.5.6); from 10.2, before 10.2.1.8 (fixed in 10.2.1.8)
Published 2019-01-24. Last modified 2026-06-17.