First published: Wed Aug 22 2012(Updated: )
Cross-site scripting (XSS) vulnerability in McAfee Email and Web Security (EWS) 5.5 through Patch 6 and 5.6 through Patch 3, and McAfee Email Gateway (MEG) 7.0.0 and 7.0.1, allows remote attackers to inject arbitrary web script or HTML via vectors related to the McAfee Security Appliance Management Console/Dashboard.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
McAfee Email and Web Security | =5.5 | |
McAfee Email and Web Security | =5.6 | |
McAfee Email Gateway | =7.0.0 | |
McAfee Email Gateway | =7.0.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2012-4597 has a medium severity rating due to its potential for cross-site scripting attacks.
To fix CVE-2012-4597, update to McAfee Email and Web Security version 5.6 Patch 4 or later and McAfee Email Gateway version 7.0.2 or later.
CVE-2012-4597 affects McAfee Email and Web Security versions 5.5 through Patch 6 and 5.6 through Patch 3, as well as McAfee Email Gateway versions 7.0.0 and 7.0.1.
CVE-2012-4597 is a cross-site scripting (XSS) vulnerability.
Yes, CVE-2012-4597 can be exploited remotely by attackers to inject arbitrary web scripts or HTML.