CVE-2014-8526: Infoleak
Published Oct 29, 2014
·Updated
McAfee Network Data Loss Prevention (NDLP) before 9.3 allows local users to obtain sensitive information by reading a Java stack trace.
Affected Software
4 affected components
Mcafee Network Data Loss Prevention<=9.2.2
Mcafee Network Data Loss Prevention=8.6
Mcafee Network Data Loss Prevention=9.2.0
Mcafee Network Data Loss Prevention=9.2.1
Event History
Oct 29, 2014
CVE Published
via MITRE·02:00 PM
Data Sourced
via MITRE·02:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2014-8526?
CVE-2014-8526 is rated as a medium severity vulnerability due to its potential to expose sensitive information.
2
How do I fix CVE-2014-8526?
To fix CVE-2014-8526, upgrade McAfee Network Data Loss Prevention to version 9.3 or later.
3
What causes CVE-2014-8526?
CVE-2014-8526 is caused by insufficient protection against local user access to sensitive information in Java stack traces.
4
Who is affected by CVE-2014-8526?
Users operating McAfee Network Data Loss Prevention versions prior to 9.3 are affected by CVE-2014-8526.
5
What kind of information can be exposed by CVE-2014-8526?
CVE-2014-8526 can allow local users to access sensitive information that is contained within the Java stack trace.