CVE-2018-6660
- EPSS 1.08%
- Veröffentlicht 02.04.2018 13:29:00
- Zuletzt bearbeitet 21.11.2024 04:11:04
Directory Traversal vulnerability in McAfee ePolicy Orchestrator (ePO) 5.3.2, 5.3.1, 5.3.0 and 5.9.0 allows administrators to use Windows alternate data streams, which could be used to bypass the file extensions, via not properly validating the path ...
CVE-2017-3980
- EPSS 3.45%
- Veröffentlicht 18.05.2017 19:29:00
- Zuletzt bearbeitet 20.04.2025 01:37:25
A directory traversal vulnerability in the ePO Extension in McAfee ePolicy Orchestrator (ePO) 5.9.0, 5.3.2, and 5.1.3 and earlier allows remote authenticated users to execute a command of their choice via an authenticated ePO session.
- EPSS 17.21%
- Veröffentlicht 14.03.2017 22:59:01
- Zuletzt bearbeitet 20.04.2025 01:37:25
SQL injection vulnerability in core services in Intel Security McAfee ePolicy Orchestrator (ePO) 5.3.2 and earlier and 5.1.3 and earlier allows attackers to alter a SQL query, which can result in disclosure of information within the database or imper...
CVE-2017-3902
- EPSS 0.34%
- Veröffentlicht 13.02.2017 16:59:00
- Zuletzt bearbeitet 20.04.2025 01:37:25
Cross-site scripting (XSS) vulnerability in the Web user interface (UI) in Intel Security ePO 5.1.3, 5.1.2, 5.1.1, and 5.1.0 allows authenticated users to inject malicious Java scripts via bypassing input validation.
CVE-2015-8765
- EPSS 1.28%
- Veröffentlicht 08.01.2016 20:59:03
- Zuletzt bearbeitet 12.04.2025 10:46:40
Intel McAfee ePolicy Orchestrator (ePO) 4.6.9 and earlier, 5.0.x, 5.1.x before 5.1.3 Hotfix 1106041, and 5.3.x before 5.3.1 Hotfix 1106041 allow remote attackers to execute arbitrary code via a crafted serialized Java object, related to the Apache Co...
CVE-2015-2859
- EPSS 0.2%
- Veröffentlicht 23.06.2015 21:59:00
- Zuletzt bearbeitet 12.04.2025 10:46:40
Intel McAfee ePolicy Orchestrator (ePO) 4.x through 4.6.9 and 5.x through 5.1.2 does not validate server names and Certification Authority names in X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obt...
CVE-2015-4559
- EPSS 0.26%
- Veröffentlicht 15.06.2015 15:59:14
- Zuletzt bearbeitet 12.04.2025 10:46:40
Cross-site scripting (XSS) vulnerability in the product deployment feature in the Java core web services in Intel McAfee ePolicy Orchestrator (ePO) before 5.1.2 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
- EPSS 45.75%
- Veröffentlicht 09.01.2015 18:59:11
- Zuletzt bearbeitet 12.04.2025 10:46:40
McAfee ePolicy Orchestrator (ePO) before 4.6.9 and 5.x before 5.1.2 uses the same secret key across different customers' installations, which allows attackers to obtain the administrator password by leveraging knowledge of the encrypted password.
- EPSS 58.22%
- Veröffentlicht 09.01.2015 18:59:10
- Zuletzt bearbeitet 12.04.2025 10:46:40
XML external entity (XXE) vulnerability in the Server Task Log in McAfee ePolicy Orchestrator (ePO) before 4.6.9 and 5.x before 5.1.2 allows remote authenticated users to read arbitrary files via the conditionXML parameter to the taskLogTable to orio...
CVE-2014-2205
- EPSS 0.36%
- Veröffentlicht 26.02.2014 15:55:08
- Zuletzt bearbeitet 12.04.2025 10:46:40
The Import and Export Framework in McAfee ePolicy Orchestrator (ePO) before 4.6.7 Hotfix 940148 allows remote authenticated users with permissions to add dashboards to read arbitrary files by importing a crafted XML file, related to an XML External E...