CVE-2016-3652 | Symantec Endpoint Protection Manager up to 12.1.6 MP4 PHP JSESSIONID cross site scripting (SYM16-011 / EDB-40041)
A vulnerability classified as problematic was found in Symantec Endpoint Protection Manager up to 12.1.6 MP4. This vulnerability affects unknown code of the component PHP JSESSIONID Handler. The manipulation leads to cross site scripting.
This vulnerability was named CVE-2016-3652. The attack can be initiated remotely. Furthermore, there is an exploit available.
It is recommended to apply a patch to fix this issue.