6.3

CVE-2014-2205

Exploit

The Import and Export Framework in McAfee ePolicy Orchestrator (ePO) before 4.6.7 Hotfix 940148 allows remote authenticated users with permissions to add dashboards to read arbitrary files by importing a crafted XML file, related to an XML External Entity (XXE) issue.

Data is provided by the National Vulnerability Database (NVD)
McafeeEpolicy Orchestrator Version <= 4.6.7
McafeeEpolicy Orchestrator Version4.6.0
McafeeEpolicy Orchestrator Version4.6.1
McafeeEpolicy Orchestrator Version4.6.2
McafeeEpolicy Orchestrator Version4.6.3
McafeeEpolicy Orchestrator Version4.6.4
McafeeEpolicy Orchestrator Version4.6.5
McafeeEpolicy Orchestrator Version4.6.6
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 0.36% 0.55
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
nvd@nist.gov 6.3 6.8 6.9
AV:N/AC:M/Au:S/C:C/I:N/A:N