Mcafee

Epolicy Orchestrator

86 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.16%
  • Veröffentlicht 23.03.2022 14:15:07
  • Zuletzt bearbeitet 21.11.2024 06:39:30

A blind SQL injection vulnerability in McAfee Enterprise ePolicy Orchestrator (ePO) prior to 5.10 Update 13 allows a remote authenticated attacker to potentially obtain information from the ePO database. The data obtained is dependent on the privileg...

  • EPSS 0.25%
  • Veröffentlicht 22.10.2021 11:15:07
  • Zuletzt bearbeitet 21.11.2024 06:06:19

Cross-Site Scripting vulnerability in McAfee ePolicy Orchestrator (ePO) prior to 5.10 Update 11 allows ePO administrators to inject arbitrary web script or HTML via a specific parameter where the administrator's entries were not correctly sanitized.

  • EPSS 0.21%
  • Veröffentlicht 22.10.2021 11:15:07
  • Zuletzt bearbeitet 21.11.2024 06:06:19

Stored Cross-Site Scripting vulnerability in McAfee ePolicy Orchestrator (ePO) prior to 5.10 Update 11 allows ePO administrators to inject arbitrary web script or HTML via multiple parameters where the administrator's entries were not correctly sanit...

Warnung
  • EPSS 0.82%
  • Veröffentlicht 24.08.2021 15:15:09
  • Zuletzt bearbeitet 21.11.2024 06:22:13

ASN.1 strings are represented internally within OpenSSL as an ASN1_STRING structure which contains a buffer holding the string data and a field holding the buffer length. This contrasts with normal C strings which are repesented as a buffer for the s...

  • EPSS 0.13%
  • Veröffentlicht 21.07.2021 15:16:03
  • Zuletzt bearbeitet 21.11.2024 06:03:06

Vulnerability in the Java SE product of Oracle Java SE (component: JNDI). The supported version that is affected is Java SE: 7u301. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compr...

  • EPSS 3.1%
  • Veröffentlicht 12.07.2021 15:15:08
  • Zuletzt bearbeitet 21.11.2024 06:08:10

Apache Tomcat 10.0.0-M1 to 10.0.6, 9.0.0.M1 to 9.0.46 and 8.5.0 to 8.5.66 did not correctly parse the HTTP transfer-encoding request header in some circumstances leading to the possibility to request smuggling when used with a reverse proxy. Specific...

  • EPSS 0.34%
  • Veröffentlicht 12.07.2021 15:15:08
  • Zuletzt bearbeitet 21.11.2024 06:04:20

A vulnerability in Apache Tomcat allows an attacker to remotely trigger a denial of service. An error introduced as part of a change to improve error handling during non-blocking I/O meant that the error flag associated with the Request object was no...

  • EPSS 0.28%
  • Veröffentlicht 10.06.2021 07:15:07
  • Zuletzt bearbeitet 21.11.2024 05:02:11

Apache HTTP Server versions 2.4.0 to 2.4.46 Unprivileged local users can stop httpd on Windows

  • EPSS 0.27%
  • Veröffentlicht 22.04.2021 22:15:13
  • Zuletzt bearbeitet 21.11.2024 06:02:30

Vulnerability in the Java SE, Java SE Embedded, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: Libraries). Supported versions that are affected are Java SE: 7u291, 8u281, 11.0.10, 16; Java SE Embedded: 8u281; Oracle GraalVM E...

  • EPSS 0.21%
  • Veröffentlicht 26.03.2021 10:15:12
  • Zuletzt bearbeitet 21.11.2024 05:52:00

Cross-Site Scripting vulnerability in McAfee ePolicy Orchestrator (ePO) prior to 5.10 Update 10 allows ePO administrators to inject arbitrary web script or HTML via multiple parameters where the administrator's entries were not correctly sanitized.