CVE-2013-4882: SQL Injection
Multiple SQL injection vulnerabilities in McAfee ePolicy Orchestrator 4.6.6 and earlier, and the ePolicy Orchestrator (ePO) extension for McAfee Agent (MA) 4.5 and 4.6, allow remote authenticated users to execute arbitrary SQL commands via the uid parameter to (1) core/showRegisteredTypeDetails.do and (2) EPOAGENTMETA/DisplayMSAPropsDetail.do, a different vulnerability than CVE-2013-0140.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2013-4882?
CVE-2013-4882 has a CVSS score that indicates a medium severity due to its potential impact from SQL injection vulnerabilities.
How do I fix CVE-2013-4882?
To mitigate CVE-2013-4882, users should upgrade to the latest version of McAfee ePolicy Orchestrator beyond version 4.6.6.
What systems are affected by CVE-2013-4882?
CVE-2013-4882 affects McAfee ePolicy Orchestrator versions 4.6.6 and earlier, as well as the ePolicy Orchestrator extension for McAfee Agent versions 4.5 and 4.6.
Can CVE-2013-4882 be exploited remotely?
Yes, CVE-2013-4882 can be exploited remotely by authenticated users to execute arbitrary SQL commands.
What type of vulnerability is CVE-2013-4882?
CVE-2013-4882 is classified as a SQL injection vulnerability.