Is Endpoint Protection Manager Impacted by CVE-2016-4437?
search cancel

Is Endpoint Protection Manager Impacted by CVE-2016-4437?

book

Article ID: 440864

calendar_today

Updated On:

Products

Endpoint Protection

Issue/Introduction

Security administrators need to determine if Symantec Endpoint Protection Manager (SEPM), specifically versions 14.3.x and 14.4.x, is vulnerable to CVE-2016-4437.

(Note: CVE-2016-4437 is a known vulnerability associated with the Apache Shiro framework, where a remote attacker could potentially execute arbitrary code or bypass authentication.)

Environment

 

  • Product: Symantec Endpoint Protection Manager (SEPM)

  • Versions: 14.3.x, 14.4.x, and all other versions

 

Resolution

Symantec Endpoint Protection Manager (SEPM) is not impacted by CVE-2016-4437.

This specific vulnerability targets the Apache Shiro security framework. Because SEPM does not use Apache Shiro in its architecture, it is completely immune to this vulnerability across all versions, including 14.3.x and 14.4.x.