Mcafee

Epolicy Orchestrator

86 vulnerabilities found.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 1.08%
  • Published 02.04.2018 13:29:00
  • Last modified 21.11.2024 04:11:04

Directory Traversal vulnerability in McAfee ePolicy Orchestrator (ePO) 5.3.2, 5.3.1, 5.3.0 and 5.9.0 allows administrators to use Windows alternate data streams, which could be used to bypass the file extensions, via not properly validating the path ...

  • EPSS 3.45%
  • Published 18.05.2017 19:29:00
  • Last modified 20.04.2025 01:37:25

A directory traversal vulnerability in the ePO Extension in McAfee ePolicy Orchestrator (ePO) 5.9.0, 5.3.2, and 5.1.3 and earlier allows remote authenticated users to execute a command of their choice via an authenticated ePO session.

  • EPSS 17.21%
  • Published 14.03.2017 22:59:01
  • Last modified 20.04.2025 01:37:25

SQL injection vulnerability in core services in Intel Security McAfee ePolicy Orchestrator (ePO) 5.3.2 and earlier and 5.1.3 and earlier allows attackers to alter a SQL query, which can result in disclosure of information within the database or imper...

  • EPSS 0.34%
  • Published 13.02.2017 16:59:00
  • Last modified 20.04.2025 01:37:25

Cross-site scripting (XSS) vulnerability in the Web user interface (UI) in Intel Security ePO 5.1.3, 5.1.2, 5.1.1, and 5.1.0 allows authenticated users to inject malicious Java scripts via bypassing input validation.

  • EPSS 1.28%
  • Published 08.01.2016 20:59:03
  • Last modified 12.04.2025 10:46:40

Intel McAfee ePolicy Orchestrator (ePO) 4.6.9 and earlier, 5.0.x, 5.1.x before 5.1.3 Hotfix 1106041, and 5.3.x before 5.3.1 Hotfix 1106041 allow remote attackers to execute arbitrary code via a crafted serialized Java object, related to the Apache Co...

  • EPSS 0.2%
  • Published 23.06.2015 21:59:00
  • Last modified 12.04.2025 10:46:40

Intel McAfee ePolicy Orchestrator (ePO) 4.x through 4.6.9 and 5.x through 5.1.2 does not validate server names and Certification Authority names in X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obt...

  • EPSS 0.26%
  • Published 15.06.2015 15:59:14
  • Last modified 12.04.2025 10:46:40

Cross-site scripting (XSS) vulnerability in the product deployment feature in the Java core web services in Intel McAfee ePolicy Orchestrator (ePO) before 5.1.2 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

Exploit
  • EPSS 45.75%
  • Published 09.01.2015 18:59:11
  • Last modified 12.04.2025 10:46:40

McAfee ePolicy Orchestrator (ePO) before 4.6.9 and 5.x before 5.1.2 uses the same secret key across different customers' installations, which allows attackers to obtain the administrator password by leveraging knowledge of the encrypted password.

Exploit
  • EPSS 58.22%
  • Published 09.01.2015 18:59:10
  • Last modified 12.04.2025 10:46:40

XML external entity (XXE) vulnerability in the Server Task Log in McAfee ePolicy Orchestrator (ePO) before 4.6.9 and 5.x before 5.1.2 allows remote authenticated users to read arbitrary files via the conditionXML parameter to the taskLogTable to orio...

Exploit
  • EPSS 0.36%
  • Published 26.02.2014 15:55:08
  • Last modified 12.04.2025 10:46:40

The Import and Export Framework in McAfee ePolicy Orchestrator (ePO) before 4.6.7 Hotfix 940148 allows remote authenticated users with permissions to add dashboards to read arbitrary files by importing a crafted XML file, related to an XML External E...