First published: Wed Oct 29 2014(Updated: )
McAfee Network Data Loss Prevention (NDLP) before 9.3 logs session IDs, which allows local users to obtain sensitive information by reading the audit log.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
McAfee Network Data Loss Prevention | <=9.2.2 | |
McAfee Network Data Loss Prevention | =8.6 | |
McAfee Network Data Loss Prevention | =9.2.0 | |
McAfee Network Data Loss Prevention | =9.2.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2014-8528 has a medium severity rating due to its potential exposure of sensitive information.
To fix CVE-2014-8528, upgrade to McAfee Network Data Loss Prevention version 9.3 or later.
CVE-2014-8528 affects McAfee Network Data Loss Prevention versions 9.2.2 and earlier, including versions 8.6, 9.2.0, and 9.2.1.
Local users can access sensitive session IDs from the audit log due to the logging functionality exposed in CVE-2014-8528.
There are no officially documented workarounds for CVE-2014-8528; upgrading to a patched version is recommended.