First published: Tue Mar 14 2017(Updated: )
SQL injection vulnerability in Intel Security VirusScan Enterprise Linux (VSEL) 2.0.3 (and earlier) allows remote authenticated users to obtain product information via a crafted HTTP request parameter.
Credit: secure@intel.com
Affected Software | Affected Version | How to fix |
---|---|---|
McAfee VirusScan Enterprise | <=2.0.3 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2016-8025 has a severity score that indicates it is a critical SQL injection vulnerability.
To fix CVE-2016-8025, upgrade Intel Security VirusScan Enterprise Linux to version 2.0.4 or later.
CVE-2016-8025 affects remote authenticated users of Intel Security VirusScan Enterprise Linux version 2.0.3 and earlier.
An attacker exploiting CVE-2016-8025 can obtain sensitive product information through specially crafted HTTP request parameters.
Yes, CVE-2016-8025 can be exploited with minimal effort if the attacker has authenticated access.