Show filters
5 Total Results
Displaying 1-5 of 5
Sort by:
Attacker Value
Unknown

McAfee ePolicy Orchestrator (ePO) - OS Command Injection vulnerability

Disclosure Date: June 13, 2018 (last updated November 08, 2023)
OS Command Injection vulnerability in McAfee ePolicy Orchestrator (ePO) 5.9.0, 5.3.2, 5.3.1, 5.1.3, 5.1.2, 5.1.1, and 5.1.0 allows attackers to run arbitrary OS commands with limited privileges via not sanitizing the user input data before exporting it into a CSV format output.
0
Attacker Value
Unknown

CVE-2017-3902

Disclosure Date: February 13, 2017 (last updated November 26, 2024)
Cross-site scripting (XSS) vulnerability in the Web user interface (UI) in Intel Security ePO 5.1.3, 5.1.2, 5.1.1, and 5.1.0 allows authenticated users to inject malicious Java scripts via bypassing input validation.
0
Attacker Value
Unknown

CVE-2015-2859

Disclosure Date: June 23, 2015 (last updated October 05, 2023)
Intel McAfee ePolicy Orchestrator (ePO) 4.x through 4.6.9 and 5.x through 5.1.2 does not validate server names and Certification Authority names in X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.
0
Attacker Value
Unknown

CVE-2015-0922

Disclosure Date: January 09, 2015 (last updated October 05, 2023)
McAfee ePolicy Orchestrator (ePO) before 4.6.9 and 5.x before 5.1.2 uses the same secret key across different customers' installations, which allows attackers to obtain the administrator password by leveraging knowledge of the encrypted password.
0
Attacker Value
Unknown

CVE-2015-0921

Disclosure Date: January 09, 2015 (last updated October 05, 2023)
XML external entity (XXE) vulnerability in the Server Task Log in McAfee ePolicy Orchestrator (ePO) before 4.6.9 and 5.x before 5.1.2 allows remote authenticated users to read arbitrary files via the conditionXML parameter to the taskLogTable to orionUpdateTableFilter.do.
0