CVE-2017-3907: McAfee Threat Intelligence Exchange (TIE) Server - Code Injection vulnerability
Published Jun 13, 2018
·Updated
Code Injection vulnerability in the ePolicy Orchestrator (ePO) extension in McAfee Threat Intelligence Exchange (TIE) Server 2.1.0 and earlier allows remote attackers to execute arbitrary HTML code to be reflected in the response web page via unspecified vector.
Affected Software
1 affected component
McAfee McAfee Threat Intelligence Exchange=2.1.0
Event History
Jun 13, 2018
CVE Published
via MITRE·09:00 PM
Data Sourced
via MITRE·09:00 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2017-3907?
CVE-2017-3907 is classified as a medium severity vulnerability.
2
How do I fix CVE-2017-3907?
To remediate CVE-2017-3907, update McAfee Threat Intelligence Exchange to a version later than 2.1.0.
3
What products are affected by CVE-2017-3907?
CVE-2017-3907 affects McAfee Threat Intelligence Exchange version 2.1.0 and earlier.
4
What type of vulnerability is CVE-2017-3907?
CVE-2017-3907 is a code injection vulnerability.
5
Can CVE-2017-3907 allow remote code execution?
Yes, CVE-2017-3907 allows remote attackers to execute arbitrary HTML code on the affected system.