Are SEPM and LUA affected by CVE-2023-41080 ?
search cancel

Are SEPM and LUA affected by CVE-2023-41080 ?

book

Article ID: 272914

calendar_today

Updated On:

Products

Endpoint Protection

Issue/Introduction

Are Symantec Endpoint Protection Manager(SEPM) and LiveUpdate Administrator(LUA) affected by CVE-2023-41080 ?

CVE-2023-41080: URL Redirection to Untrusted Site ('Open Redirect') vulnerability in FORM authentication feature Apache Tomcat.
  https://nvd.nist.gov/vuln/detail/CVE-2023-41080
  https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-41080

Resolution

LUA:
LUA is not impacted as it is not the default web App (ROOT) and does not use FORM authentication.

SEPM:
SEPM deployment in Tomcat under the ROOT application ("old" sepm) does not use FORM authentication, so SEPM is not vulnerable to this CVE.