CVE-2016-8027: SQL Injection
SQL injection vulnerability in core services in Intel Security McAfee ePolicy Orchestrator (ePO) 5.3.2 and earlier and 5.1.3 and earlier allows attackers to alter a SQL query, which can result in disclosure of information within the database or impersonation of an agent without authentication via a specially crafted HTTP post.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2016-8027?
CVE-2016-8027 has a high severity rating due to the potential for SQL injection attacks that can compromise database confidentiality.
How do I fix CVE-2016-8027?
To fix CVE-2016-8027, update Intel Security McAfee ePolicy Orchestrator to version 5.3.3 or later, or 5.1.4 or later.
What systems are affected by CVE-2016-8027?
CVE-2016-8027 affects Intel Security McAfee ePolicy Orchestrator versions 5.3.2 and earlier and 5.1.3 and earlier.
What kind of attack can be executed using CVE-2016-8027?
CVE-2016-8027 allows attackers to perform SQL injection, which can lead to unauthorized access to database information or impersonation of agents.
Is there a temporary workaround for CVE-2016-8027?
While the best course of action is to update, disabling certain features or restricting database access may serve as temporary mitigations for CVE-2016-8027.