CVE-2015-0921: Medium severity mcafee epolicy orchestrator vulnerability
Published Jan 9, 2015
·Updated
XML external entity (XXE) vulnerability in the Server Task Log in McAfee ePolicy Orchestrator (ePO) before 4.6.9 and 5.x before 5.1.2 allows remote authenticated users to read arbitrary files via the conditionXML parameter to the taskLogTable to orionUpdateTableFilter.do.
Affected Software
5 affected components
McAfee ePolicy Orchestrator<=4.6.8
McAfee ePolicy Orchestrator=5.0.0
McAfee ePolicy Orchestrator=5.0.1
McAfee ePolicy Orchestrator=5.1.0
McAfee ePolicy Orchestrator=5.1.1
Remediation
Event History
Jan 9, 2015
CVE Published
via MITRE·06:00 PM
Data Sourced
via MITRE·06:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2015-0921?
CVE-2015-0921 has a medium severity rating due to its potential for information disclosure.
2
How do I fix CVE-2015-0921?
To fix CVE-2015-0921, upgrade to McAfee ePolicy Orchestrator version 4.6.9 or 5.1.2 or later.
3
Who is affected by CVE-2015-0921?
CVE-2015-0921 affects all versions of McAfee ePolicy Orchestrator prior to 4.6.9 and 5.x before 5.1.2.
4
What type of vulnerability is CVE-2015-0921?
CVE-2015-0921 is an XML External Entity (XXE) vulnerability that allows remote file access.
5
Can authenticated users exploit CVE-2015-0921?
Yes, remote authenticated users can exploit CVE-2015-0921 to read arbitrary files.