CVE-2015-1619: XSS
Published Feb 17, 2015
·Updated
Cross-site scripting (XSS) vulnerability in the Secure Web Mail Client user interface in McAfee Email Gateway (MEG) 7.6.x before 7.6.3.2, 7.5.x before 75.6, 7.0.x through 7.0.5, 5.6, and earlier allows remote authenticated users to inject arbitrary web script or HTML via unspecified tokens in Digest messages.
Affected Software
17 affected components
McAfee Email Gateway<=5.6
McAfee Email Gateway=7.0
McAfee Email Gateway=7.0.1
McAfee Email Gateway=7.0.2
McAfee Email Gateway=7.0.3
McAfee Email Gateway=7.0.4
McAfee Email Gateway=7.0.5
McAfee Email Gateway=7.5
McAfee Email Gateway=7.5.1
McAfee Email Gateway=7.5.2
McAfee Email Gateway=7.5.3
McAfee Email Gateway=7.5.4
McAfee Email Gateway=7.5.5
McAfee Email Gateway=7.6
McAfee Email Gateway=7.6.1
McAfee Email Gateway=7.6.2
McAfee Email Gateway=7.6.3
Event History
Feb 17, 2015
CVE Published
via MITRE·03:00 PM
Data Sourced
via MITRE·03:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2015-1619?
CVE-2015-1619 is considered a medium-severity cross-site scripting vulnerability.
2
How do I fix CVE-2015-1619?
To fix CVE-2015-1619, upgrade to McAfee Email Gateway versions 7.6.3.2, 7.5.6, or later.
3
Who is affected by CVE-2015-1619?
CVE-2015-1619 affects users of McAfee Email Gateway versions 5.6 to 7.6.2.
4
What type of vulnerability is CVE-2015-1619?
CVE-2015-1619 is a cross-site scripting (XSS) vulnerability.
5
Can CVE-2015-1619 be exploited by unauthenticated users?
No, CVE-2015-1619 requires remote authenticated users to exploit the vulnerability.