Session fixation vulnerability in the web interface in McAfee Network Security Manager (NSM) before 8.2.7.42.2 and McAfee Network Data Loss Prevention (NDLP) before 9.3.4.1.5 allows remote attackers to disclose sensitive information or manipulate the database via a crafted authentication cookie.
References
Configurations
Configuration 1 (hide)
|
History
07 Nov 2023, 02:44
Type | Values Removed | Values Added |
---|---|---|
References | () https://kc.mcafee.com/corporate/index?page=content&id=SB10192 - | |
References | () https://kc.mcafee.com/corporate/index?page=content&id=SB10198 - |
Information
Published : 2018-06-13 20:29
Updated : 2024-02-28 16:25
NVD link : CVE-2017-3968
Mitre link : CVE-2017-3968
CVE.ORG link : CVE-2017-3968
JSON object : View
Products Affected
mcafee
- network_security_manager
- network_data_loss_prevention
CWE
CWE-384
Session Fixation