First published: Tue Mar 14 2017(Updated: )
SQL injection vulnerability in Intel Security Advanced Threat Defense (ATD) Linux 3.6.0 and earlier allows remote authenticated users to obtain product information via a crafted HTTP request parameter.
Credit: secure@intel.com
Affected Software | Affected Version | How to fix |
---|---|---|
McAfee Advanced Threat Defense | <=3.8.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2017-3899 has a severity rating of medium due to its potential to leak product information.
To fix CVE-2017-3899, update Intel Security Advanced Threat Defense to version 3.8.0 or later.
CVE-2017-3899 affects remote authenticated users of Intel Security Advanced Threat Defense versions 3.6.0 and earlier.
CVE-2017-3899 is categorized as an SQL injection vulnerability.
Yes, CVE-2017-3899 can be exploited remotely by authenticated users through a crafted HTTP request.