First published: Sun Mar 23 2014(Updated: )
SQL injection vulnerability in jsp/reports/ReportsAudit.jsp in McAfee Asset Manager 6.6 allows remote authenticated users to execute arbitrary SQL commands via the username of an audit report (aka user parameter).
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
McAfee Asset Manager | =6.6 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2014-2587 is classified as a medium severity vulnerability due to its SQL injection risk, which allows authenticated users to execute arbitrary SQL commands.
To fix CVE-2014-2587, ensure that your McAfee Asset Manager is updated to a version that addresses this SQL injection vulnerability.
CVE-2014-2587 affects remote authenticated users of McAfee Asset Manager version 6.6.
CVE-2014-2587 is an SQL injection vulnerability allowing attackers to manipulate database queries through user input.
CVE-2014-2587 can be exploited to execute arbitrary SQL commands using the username parameter in audit report requests.