First published: Fri Mar 27 2015(Updated: )
Multiple cross-site request forgery (CSRF) vulnerabilities in the ePO extension in McAfee Data Loss Prevention Endpoint (DLPe) before 9.3 Patch 4 Hotfix 16 (9.3.416.4) allow remote attackers to hijack the authentication of users for requests that (1) obtain sensitive information or (2) modify the database via unspecified vectors.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
McAfee Data Loss Prevention Endpoint | <=9.3.400 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2015-2759 has been rated as critical due to the potential for remote attackers to hijack user authentication.
To mitigate CVE-2015-2759, update McAfee Data Loss Prevention Endpoint to version 9.3 Patch 4 Hotfix 16 or later.
CVE-2015-2759 affects users of McAfee Data Loss Prevention Endpoint versions prior to 9.3 Patch 4 Hotfix 16.
CVE-2015-2759 allows attackers to execute cross-site request forgery (CSRF) attacks, potentially obtaining sensitive information or altering data.
If immediate updates are not possible for CVE-2015-2759, consider implementing application-level security measures to mitigate CSRF attacks.