CVE-2017-4011: XSS
Embedding Script (XSS) in HTTP Headers vulnerability in the server in McAfee Network Data Loss Prevention (NDLP) 9.3.x allows remote attackers to get session/cookie information via modification of the HTTP request.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2017-4011?
CVE-2017-4011 is considered a medium severity vulnerability due to its potential to allow remote attackers access to sensitive session and cookie information.
How do I fix CVE-2017-4011?
To mitigate CVE-2017-4011, ensure that you update McAfee Network Data Loss Prevention to version 9.3.1 or higher.
What products are affected by CVE-2017-4011?
CVE-2017-4011 affects McAfee Network Data Loss Prevention versions prior to 9.3.1.
What type of vulnerability is CVE-2017-4011?
CVE-2017-4011 is classified as an embedding script cross-site scripting (XSS) vulnerability.
Can CVE-2017-4011 be exploited remotely?
Yes, CVE-2017-4011 can be remotely exploited, allowing attackers to modify HTTP requests to gain access to session and cookie data.