CVE-2017-3933: XSS
Published Oct 31, 2017
·Updated
Embedding Script (XSS) in HTTP Headers vulnerability in McAfee Network Data Loss Prevention (NDLP) 9.3.x allows remote authenticated users to view confidential information via a cross site request forgery attack.
Affected Software
5 affected components
Mcafee Network Data Loss Prevention=9.3.0
Mcafee Network Data Loss Prevention=9.3.1
Mcafee Network Data Loss Prevention=9.3.2
Mcafee Network Data Loss Prevention=9.3.3
Mcafee Network Data Loss Prevention=9.3.4
Remediation
Event History
Oct 31, 2017
CVE Published
via MITRE·02:00 PM
Data Sourced
via MITRE·02:00 PM
DescriptionWeakness
Frequently Asked Questions
1
What is the severity of CVE-2017-3933?
CVE-2017-3933 has a medium severity rating due to its potential to expose confidential information through cross-site scripting.
2
How do I fix CVE-2017-3933?
To fix CVE-2017-3933, update McAfee Network Data Loss Prevention to the latest version as recommended by the vendor.
3
Who is affected by CVE-2017-3933?
CVE-2017-3933 affects McAfee Network Data Loss Prevention versions 9.3.0 through 9.3.4.
4
What type of attack is facilitated by CVE-2017-3933?
CVE-2017-3933 facilitates a cross-site scripting (XSS) attack through HTTP headers.
5
Can remote users exploit CVE-2017-3933?
Yes, remote authenticated users can exploit CVE-2017-3933 to view sensitive information.