4

CVE-2012-4594

McAfee ePolicy Orchestrator (ePO) 4.6.1 and earlier allows remote authenticated users to bypass intended access restrictions, and obtain sensitive information from arbitrary reporting panels, via a modified ID value in a console URL.

Data is provided by the National Vulnerability Database (NVD)
McafeeEpolicy Orchestrator Version <= 4.6.1
McafeeEpolicy Orchestrator Version2.0
McafeeEpolicy Orchestrator Version2.5
McafeeEpolicy Orchestrator Version2.5 Updatesp1
McafeeEpolicy Orchestrator Version2.5.1
McafeeEpolicy Orchestrator Version3.0
McafeeEpolicy Orchestrator Version3.0 Updatesp2a
McafeeEpolicy Orchestrator Version3.5.0
McafeeEpolicy Orchestrator Version3.6.0
McafeeEpolicy Orchestrator Version3.6.1
McafeeEpolicy Orchestrator Version4.0
McafeeEpolicy Orchestrator Version4.5.0
McafeeEpolicy Orchestrator Version4.6.0
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 0.16% 0.33
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
nvd@nist.gov 4 8 2.9
AV:N/AC:L/Au:S/C:P/I:N/A:N