Are Symantec Endpoint Protection Manager(SEPM) and LiveUpdate Administrator(LUA) affected by CVE-2023-41080 ?
CVE-2023-41080: URL Redirection to Untrusted Site ('Open Redirect') vulnerability in FORM authentication feature Apache Tomcat.
https://nvd.nist.gov/vuln/detail/CVE-2023-41080
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-41080
LUA:
LUA is not impacted as it is not the default web App (ROOT) and does not use FORM authentication.
SEPM:
SEPM deployment in Tomcat under the ROOT application ("old" sepm) does not use FORM authentication, so SEPM is not vulnerable to this CVE.