A reflected cross-site scripting (XSS) vulnerability in McAfee Enterprise ePolicy Orchestrator (ePO) prior to 5.10 Update 13 allows a remote attacker to potentially obtain access to an ePO administrator's session by convincing the attacker to click on a carefully crafted link. This would lead to limited access to sensitive information and limited ability to alter some information in ePO due to the area of the User Interface the vulnerability is present in.
References
Link | Resource |
---|---|
https://kc.mcafee.com/corporate/index?page=content&id=SB10379 | Broken Link |
https://kc.mcafee.com/corporate/index?page=content&id=SB10379 | Broken Link |
Configurations
Configuration 1 (hide)
|
History
21 Nov 2024, 06:39
Type | Values Removed | Values Added |
---|---|---|
CVSS |
v2 : v3 : |
v2 : 4.3
v3 : 5.4 |
References | () https://kc.mcafee.com/corporate/index?page=content&id=SB10379 - Broken Link |
15 Nov 2023, 19:06
Type | Values Removed | Values Added |
---|---|---|
CWE | CWE-79 | |
References | () https://kc.mcafee.com/corporate/index?page=content&id=SB10379 - Broken Link |
07 Nov 2023, 03:41
Type | Values Removed | Values Added |
---|---|---|
CWE | ||
References | () https://kc.mcafee.com/corporate/index?page=content&id=SB10379 - |
Information
Published : 2022-03-23 15:15
Updated : 2024-11-21 06:39
NVD link : CVE-2022-0857
Mitre link : CVE-2022-0857
CVE.ORG link : CVE-2022-0857
JSON object : View
Products Affected
mcafee
- epolicy_orchestrator
CWE
CWE-79
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')