CVE-2014-8528: Infoleak
Published Oct 29, 2014
·Updated
McAfee Network Data Loss Prevention (NDLP) before 9.3 logs session IDs, which allows local users to obtain sensitive information by reading the audit log.
Affected Software
4 affected components
Mcafee Network Data Loss Prevention<=9.2.2
Mcafee Network Data Loss Prevention=8.6
Mcafee Network Data Loss Prevention=9.2.0
Mcafee Network Data Loss Prevention=9.2.1
Event History
Oct 29, 2014
CVE Published
via MITRE·02:00 PM
Data Sourced
via MITRE·02:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2014-8528?
CVE-2014-8528 has a medium severity rating due to its potential exposure of sensitive information.
2
How do I fix CVE-2014-8528?
To fix CVE-2014-8528, upgrade to McAfee Network Data Loss Prevention version 9.3 or later.
3
What versions of McAfee Network Data Loss Prevention are affected by CVE-2014-8528?
CVE-2014-8528 affects McAfee Network Data Loss Prevention versions 9.2.2 and earlier, including versions 8.6, 9.2.0, and 9.2.1.
4
What kind of information can local users access through CVE-2014-8528?
Local users can access sensitive session IDs from the audit log due to the logging functionality exposed in CVE-2014-8528.
5
Is a workaround available for CVE-2014-8528?
There are no officially documented workarounds for CVE-2014-8528; upgrading to a patched version is recommended.