CVE-2012-4585: Medium severity mcafee email and web security vulnerability
Published Aug 22, 2012
·Updated
McAfee Email and Web Security (EWS) 5.x before 5.5 Patch 6 and 5.6 before Patch 3, and McAfee Email Gateway (MEG) 7.0 before Patch 1, allows remote authenticated users to read arbitrary files via a crafted URL.
Affected Software
4 affected components
McAfee Email and Web Security=5.0
McAfee Email and Web Security=5.5
McAfee Email and Web Security=5.6
McAfee Email Gateway=7.0
Event History
Aug 22, 2012
CVE Published
via MITRE·10:00 AM
Data Sourced
via MITRE·10:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2012-4585?
CVE-2012-4585 is considered a medium severity vulnerability.
2
How do I fix CVE-2012-4585?
To fix CVE-2012-4585, update McAfee Email and Web Security to version 5.5 Patch 6 or 5.6 Patch 3, and McAfee Email Gateway to version 7.0 Patch 1.
3
Who is affected by CVE-2012-4585?
CVE-2012-4585 affects users of McAfee Email and Web Security versions 5.0, 5.5, 5.6 and McAfee Email Gateway version 7.0.
4
What types of attacks are possible due to CVE-2012-4585?
CVE-2012-4585 allows remote authenticated users to read arbitrary files on the server through crafted URLs.
5
When was CVE-2012-4585 reported?
CVE-2012-4585 was reported in October 2012.