CVE-2015-1616: SQL Injection
SQL injection vulnerability in the ePO extension in McAfee Data Loss Prevention Endpoint (DLPe) before 9.3.400 allows remote authenticated ePO users to execute arbitrary SQL commands via unspecified vectors.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2015-1616?
CVE-2015-1616 is considered a high-severity vulnerability due to its potential for remote SQL command execution.
How do I fix CVE-2015-1616?
To remediate CVE-2015-1616, it is recommended to update McAfee Data Loss Prevention Endpoint to version 9.3.400 or later.
What kind of attacks can be performed due to CVE-2015-1616?
CVE-2015-1616 allows remote authenticated users to execute arbitrary SQL commands, potentially leading to unauthorized data access or manipulation.
Who is affected by CVE-2015-1616?
CVE-2015-1616 affects remote authenticated users of McAfee Data Loss Prevention Endpoint versions prior to 9.3.400.
When was CVE-2015-1616 published?
CVE-2015-1616 was published on January 27, 2015.