First published: Tue Feb 17 2015(Updated: )
Cross-site scripting (XSS) vulnerability in the ePO extension in McAfee Data Loss Prevention Endpoint (DLPe) before 9.3.400 allows remote authenticated users to inject arbitrary web script or HTML via unspecified vectors.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Symantec Data Loss Prevention | <=9.3.300 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2015-1617 is classified as a high severity vulnerability due to its potential impact on user data and application security.
To fix CVE-2015-1617, upgrade McAfee Data Loss Prevention Endpoint to version 9.3.400 or later.
CVE-2015-1617 affects users of McAfee Data Loss Prevention Endpoint versions prior to 9.3.400.
CVE-2015-1617 is a Cross-site scripting (XSS) vulnerability that allows injection of arbitrary web scripts.
Yes, CVE-2015-1617 can be exploited by remote authenticated users.