First published: Fri Jan 09 2015(Updated: )
XML external entity (XXE) vulnerability in the Server Task Log in McAfee ePolicy Orchestrator (ePO) before 4.6.9 and 5.x before 5.1.2 allows remote authenticated users to read arbitrary files via the conditionXML parameter to the taskLogTable to orionUpdateTableFilter.do.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
McAfee ePolicy Orchestrator | <=4.6.8 | |
McAfee ePolicy Orchestrator | =5.0.0 | |
McAfee ePolicy Orchestrator | =5.0.1 | |
McAfee ePolicy Orchestrator | =5.1.0 | |
McAfee ePolicy Orchestrator | =5.1.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.