CVE-2013-0140: SQL Injection
SQL injection vulnerability in the Agent-Handler component in McAfee ePolicy Orchestrator (ePO) before 4.5.7 and 4.6.x before 4.6.6 allows remote attackers to execute arbitrary SQL commands via a crafted request over the Agent-Server communication channel.
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability description for CVE-2013-0140?
CVE-2013-0140 is an SQL injection vulnerability in the Agent-Handler component of McAfee ePolicy Orchestrator that allows remote attackers to execute arbitrary SQL commands.
What versions of McAfee ePolicy Orchestrator are affected by CVE-2013-0140?
CVE-2013-0140 affects McAfee ePolicy Orchestrator versions prior to 4.5.7 and 4.6.x before 4.6.6.
What is the potential impact of CVE-2013-0140?
The potential impact of CVE-2013-0140 is the execution of arbitrary SQL commands by remote attackers.
How can I remediate CVE-2013-0140?
To remediate CVE-2013-0140, upgrade to McAfee ePolicy Orchestrator version 4.5.7 or 4.6.6 and later.
Is there a workaround for CVE-2013-0140?
There are currently no public workarounds for CVE-2013-0140, and upgrading is the recommended action.