CVE-2018-12243: Symantec Messaging Gateway
High severity, CVSS 8.8. EPSS: 0.8% chance of exploitation in the next 30 days.
The Symantec Messaging Gateway product prior to 10.6.6 may be susceptible to a XML external entity (XXE) exploit, which is a type of issue where XML input containing a reference to an external entity is processed by a weakly configured XML parser. The attack uses file URI schemes or relative paths in the system identifier to access files that should not normally be accessible.
Affected products
- Symantec Messaging Gateway: before 10.6.6 (fixed in 10.6.6)
Published 2018-09-19. Last modified 2026-06-17.