First published: Fri Mar 27 2015(Updated: )
The ePO extension in McAfee Data Loss Prevention Endpoint (DLPe) before 9.3 Patch 4 Hotfix 16 (9.3.416.4) allows remote authenticated users to obtain sensitive information, modify the database, or possibly have other unspecified impact via a crafted URL.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
McAfee Data Loss Prevention Endpoint | <=9.3.400 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2015-2758 has been classified as a critical severity vulnerability.
To mitigate CVE-2015-2758, upgrade to McAfee Data Loss Prevention Endpoint version 9.3 Patch 4 Hotfix 16 or later.
CVE-2015-2758 can be exploited by remote authenticated users to obtain sensitive information or modify the database.
CVE-2015-2758 affects McAfee Data Loss Prevention Endpoint versions earlier than 9.3 Patch 4 Hotfix 16.
Organizations using vulnerable versions of McAfee Data Loss Prevention Endpoint may be at risk from attacks facilitated by CVE-2015-2758.