Mcafee

Epolicy Orchestrator

86 vulnerabilities found.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.18%
  • Published 17.11.2023 10:15:08
  • Last modified 21.11.2024 08:41:47

An open redirect vulnerability in ePolicy Orchestrator prior to 5.10.0 CP1 Update 2, allows a remote low privileged user to modify the URL parameter for the purpose of redirecting URL request(s) to a malicious site. This impacts the dashboard area o...

  • EPSS 0.34%
  • Published 17.11.2023 10:15:07
  • Last modified 21.11.2024 08:41:46

A Cross Site Request Forgery vulnerability in ePolicy Orchestrator prior to 5.10.0 CP1 Update 2 allows a remote low privilege user to successfully add a new user with administrator privileges to the ePO server. This impacts the dashboard area of the...

  • EPSS 0.25%
  • Published 26.07.2023 06:15:11
  • Last modified 21.11.2024 08:18:22

A reflected cross-site scripting (XSS) vulnerability in ePO prior to 5.10 SP1 Update 1allows a remote unauthenticated attacker to potentially obtain access to an ePO administrator's session by convincing the authenticated ePO administrator to click ...

  • EPSS 0.08%
  • Published 18.10.2022 10:15:10
  • Last modified 21.11.2024 07:19:19

A reflected cross-site scripting (XSS) vulnerability in ePO prior to 5.10 Update 14 allows a remote unauthenticated attacker to potentially obtain access to an ePO administrator's session by convincing the authenticated ePO administrator to click on ...

  • EPSS 0.29%
  • Published 18.10.2022 10:15:10
  • Last modified 21.11.2024 07:19:19

An External XML entity (XXE) vulnerability in ePO prior to 5.10 Update 14 can lead to an unauthenticated remote attacker to potentially trigger a Server Side Request Forgery attack. This can be exploited by mimicking the Agent Handler call to ePO and...

  • EPSS 0.21%
  • Published 23.03.2022 15:15:08
  • Last modified 21.11.2024 06:39:32

A reflected cross-site scripting (XSS) vulnerability in McAfee Enterprise ePolicy Orchestrator (ePO) prior to 5.10 Update 13 allows a remote attacker to potentially obtain access to an ePO administrator's session by convincing the attacker to click o...

  • EPSS 0.22%
  • Published 23.03.2022 15:15:08
  • Last modified 21.11.2024 06:39:32

A cross-site scripting (XSS) vulnerability in McAfee Enterprise ePolicy Orchestrator (ePO) prior to 5.10 Update 13 allows a remote attacker to potentially obtain access to an ePO administrator's session by convincing the attacker to click on a carefu...

  • EPSS 0.04%
  • Published 23.03.2022 15:15:08
  • Last modified 21.11.2024 06:39:32

McAfee Enterprise ePolicy Orchestrator (ePO) prior to 5.10 Update 13 allows a local attacker to point an ePO server to an arbitrary SQL server during the restoration of the ePO server. To achieve this the attacker would have to be logged onto the ser...

  • EPSS 0.16%
  • Published 23.03.2022 15:15:08
  • Last modified 21.11.2024 06:39:32

A XML Extended entity vulnerability in McAfee Enterprise ePolicy Orchestrator (ePO) prior to 5.10 Update 13 allows a remote administrator attacker to upload a malicious XML file through the extension import functionality. The impact is limited to som...

  • EPSS 0.29%
  • Published 23.03.2022 15:15:08
  • Last modified 21.11.2024 06:39:33

A lack of password change protection vulnerability in a depreciated API of McAfee Enterprise ePolicy Orchestrator (ePO) prior to 5.10 Update 13 allows a remote attacker to change the password of a compromised session without knowing the existing user...