First published: Tue Oct 31 2017(Updated: )
Embedding Script (XSS) in HTTP Headers vulnerability in McAfee Network Data Loss Prevention (NDLP) 9.3.x allows remote authenticated users to view confidential information via a cross site request forgery attack.
Credit: secure@intel.com
Affected Software | Affected Version | How to fix |
---|---|---|
Mcafee Network Data Loss Prevention | =9.3.0 | |
Mcafee Network Data Loss Prevention | =9.3.1 | |
Mcafee Network Data Loss Prevention | =9.3.2 | |
Mcafee Network Data Loss Prevention | =9.3.3 | |
Mcafee Network Data Loss Prevention | =9.3.4 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2017-3933 has a medium severity rating due to its potential to expose confidential information through cross-site scripting.
To fix CVE-2017-3933, update McAfee Network Data Loss Prevention to the latest version as recommended by the vendor.
CVE-2017-3933 affects McAfee Network Data Loss Prevention versions 9.3.0 through 9.3.4.
CVE-2017-3933 facilitates a cross-site scripting (XSS) attack through HTTP headers.
Yes, remote authenticated users can exploit CVE-2017-3933 to view sensitive information.