First published: Wed Jun 13 2018(Updated: )
Session fixation vulnerability in the web interface in McAfee Network Security Manager (NSM) before 8.2.7.42.2 and McAfee Network Data Loss Prevention (NDLP) before 9.3.4.1.5 allows remote attackers to disclose sensitive information or manipulate the database via a crafted authentication cookie.
Credit: psirt@mcafee.com
Affected Software | Affected Version | How to fix |
---|---|---|
Mcafee Network Data Loss Prevention | <9.3.4.1.5 | |
McAfee Network Security Manager | <8.2.7.42.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID is CVE-2017-3968.
The severity of CVE-2017-3968 is critical with a score of 9.1.
McAfee Network Security Manager (NSM) before 8.2.7.42.2 and McAfee Network Data Loss Prevention (NDLP) before 9.3.4.1.5 are affected.
An attacker can disclose sensitive information or manipulate the database using a crafted authentication cookie.
Upgrade McAfee Network Security Manager to version 8.2.7.42.2 or later and McAfee Network Data Loss Prevention to version 9.3.4.1.5 or later.