CVE-2019-9697: Symantec Management Center
Medium severity, CVSS 6.5. EPSS: 1% chance of exploitation in the next 30 days.
An information disclosure vulnerability in the Management Center (MC) REST API 2.0, 2.1, and 2.2 prior to 2.2.2.1 allows a malicious authenticated user to obtain passwords for external backup and CPL policy import servers that they might not otherwise be authorized to access.
Affected products
- Symantec Management Center: from 2.2, before 2.2.2.1 (fixed in 2.2.2.1); version 2.0 only; version 2.1 only
Published 2019-08-30. Last modified 2026-06-17.