Vulnerability record · CVE-2016-5312 · published 14 April 2017
CVE-2016-5312: Symantec Messaging Gateway charting servlet path traversal
Symantec · Messaging Gateway
The charting component in Symantec Messaging Gateway before 10.6.2 fails to sanitize the sn parameter in brightmail/servlet/com.ve.kavachart.servlet.ChartStream, allowing directory traversal. An authenticated remote user can read arbitrary files from the appliance, which may expose credentials, configuration and message data.
Description
Directory traversal vulnerability in the charting component in Symantec Messaging Gateway before 10.6.2 allows remote authenticated users to read arbitrary files via a .. (dot dot) in the sn parameter to brightmail/servlet/com.ve.kavachart.servlet.ChartStream.
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Automated analysis
high priorityThe flaw allows authenticated arbitrary file read on a security appliance, public exploit code exists and EPSS is very high, though exploitation requires valid credentials and the CVE is not in KEV.
What it is
The charting component in Symantec Messaging Gateway before 10.6.2 fails to sanitize the sn parameter in brightmail/servlet/com.ve.kavachart.servlet.ChartStream, allowing directory traversal. An authenticated remote user can read arbitrary files from the appliance, which may expose credentials, configuration and message data.
Impact
An attacker with a valid account gains read access to arbitrary files on the Messaging Gateway host, enabling credential and configuration theft that can support further compromise.
Attack surface
Reached over the network via HTTP requests to the ChartStream servlet with a crafted sn parameter containing ../ sequences; a valid authenticated session is required and no user interaction is needed.
Exploitation
Public exploit code is referenced in Exploit-DB, Packet Storm and Full Disclosure, and EPSS is high (about 0.54, 98.9th percentile), though the CVE is not listed in CISA KEV.
What to do
- Upgrade Symantec Messaging Gateway to 10.6.2 or later, which is the fixed version per the vendor advisory.
- If immediate upgrade is not possible, restrict network access to the administrative and charting interfaces to trusted management networks.
- Enforce least privilege and review accounts that can authenticate to the appliance, removing unused or shared credentials.
- Monitor vendor advisories for any updated fixed builds and apply them promptly.
Detection
- Search web or proxy logs for requests to brightmail/servlet/com.ve.kavachart.servlet.ChartStream with sn values containing ../ or encoded traversal sequences.
- Alert on ChartStream requests returning non-image content or unusually large responses that could indicate file reads.
- Correlate ChartStream access with authentication events to identify accounts performing anomalous file-retrieval requests.
- Review file access and audit logs on the appliance for reads of sensitive paths outside expected charting data.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2016-5312 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2016-5312), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.