Show filters
91 Total Results
Displaying 61-70 of 91
Sort by:
Attacker Value
Unknown
SB10240 - ePolicy Orchestrator (ePO) - Application Protection Bypass vulnerabil…
Disclosure Date: June 15, 2018 (last updated November 08, 2023)
Application Protection Bypass vulnerability in McAfee ePolicy Orchestrator (ePO) 5.3.0 through 5.3.3 and 5.9.0 through 5.9.1 allows remote authenticated users to bypass localhost only access security protection for some ePO features via a specially crafted HTTP request.
0
Attacker Value
Unknown
McAfee ePolicy Orchestrator (ePO) - OS Command Injection vulnerability
Disclosure Date: June 13, 2018 (last updated November 08, 2023)
OS Command Injection vulnerability in McAfee ePolicy Orchestrator (ePO) 5.9.0, 5.3.2, 5.3.1, 5.1.3, 5.1.2, 5.1.1, and 5.1.0 allows attackers to run arbitrary OS commands with limited privileges via not sanitizing the user input data before exporting it into a CSV format output.
0
Attacker Value
Unknown
SB10228 ePO Reflected Cross-Site Scripting vulnerability
Disclosure Date: April 02, 2018 (last updated November 08, 2023)
Reflected Cross-Site Scripting vulnerability in McAfee ePolicy Orchestrator (ePO) 5.3.2, 5.3.1, 5.3.0 and 5.9.0 allows remote authenticated users to exploit an XSS issue via not sanitizing the user input.
0
Attacker Value
Unknown
SB10228 ePO Directory Traversal vulnerability
Disclosure Date: April 02, 2018 (last updated November 08, 2023)
Directory Traversal vulnerability in McAfee ePolicy Orchestrator (ePO) 5.3.2, 5.3.1, 5.3.0 and 5.9.0 allows administrators to use Windows alternate data streams, which could be used to bypass the file extensions, via not properly validating the path when exporting a particular XML file.
0
Attacker Value
Unknown
CVE-2017-3980
Disclosure Date: May 18, 2017 (last updated November 26, 2024)
A directory traversal vulnerability in the ePO Extension in McAfee ePolicy Orchestrator (ePO) 5.9.0, 5.3.2, and 5.1.3 and earlier allows remote authenticated users to execute a command of their choice via an authenticated ePO session.
0
Attacker Value
Unknown
CVE-2016-8027
Disclosure Date: March 14, 2017 (last updated November 26, 2024)
SQL injection vulnerability in core services in Intel Security McAfee ePolicy Orchestrator (ePO) 5.3.2 and earlier and 5.1.3 and earlier allows attackers to alter a SQL query, which can result in disclosure of information within the database or impersonation of an agent without authentication via a specially crafted HTTP post.
0
Attacker Value
Unknown
CVE-2017-3902
Disclosure Date: February 13, 2017 (last updated November 26, 2024)
Cross-site scripting (XSS) vulnerability in the Web user interface (UI) in Intel Security ePO 5.1.3, 5.1.2, 5.1.1, and 5.1.0 allows authenticated users to inject malicious Java scripts via bypassing input validation.
0
Attacker Value
Unknown
CVE-2015-8765
Disclosure Date: January 08, 2016 (last updated November 25, 2024)
Intel McAfee ePolicy Orchestrator (ePO) 4.6.9 and earlier, 5.0.x, 5.1.x before 5.1.3 Hotfix 1106041, and 5.3.x before 5.3.1 Hotfix 1106041 allow remote attackers to execute arbitrary code via a crafted serialized Java object, related to the Apache Commons Collections (ACC) library.
0
Attacker Value
Unknown
CVE-2015-2859
Disclosure Date: June 23, 2015 (last updated October 05, 2023)
Intel McAfee ePolicy Orchestrator (ePO) 4.x through 4.6.9 and 5.x through 5.1.2 does not validate server names and Certification Authority names in X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.
0
Attacker Value
Unknown
CVE-2015-4559
Disclosure Date: June 15, 2015 (last updated October 05, 2023)
Cross-site scripting (XSS) vulnerability in the product deployment feature in the Java core web services in Intel McAfee ePolicy Orchestrator (ePO) before 5.1.2 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
0