vendor:
ePO
by:
Nuri Fattah
8,8
CVSS
HIGH
SQL Injection and Reflected XSS
89, 79
CWE
Product Name: ePO
Affected Version From: McAfee ePO 4.6.6 Build 176
Affected Version To: McAfee ePO 4.6.6 Build 176
Patch Exists: Yes
Related CWE: To be assigned
CPE: a:mcafee:epolicy_orchestrator
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: None
2013
Multiple vulnerabilities in McAfee ePO 4.6.6
Multiple vulnerabilities, such as Cross-Site Scripting (XSS) and SQL injection were identified in the latest version of McAfee ePO (4.6.6). All identified vulnerabilities were discovered post authentication. The SQL injection vulnerability was identified in the GET and POST requests, while the Reflected XSS vulnerability was identified in the POST requests.
Mitigation:
McAfee has released a security bulletin (SB10043) to address the identified vulnerabilities. The SQL injection vulnerability will be addressed in ePO 4.6.7 due out in late Q3 2013.