First published: Wed May 17 2017(Updated: )
Embedding Script (XSS) in HTTP Headers vulnerability in the server in McAfee Network Data Loss Prevention (NDLP) 9.3.x allows remote attackers to get session/cookie information via modification of the HTTP request.
Credit: secure@intel.com
Affected Software | Affected Version | How to fix |
---|---|---|
Mcafee Network Data Loss Prevention | <=9.3.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2017-4011 is considered a medium severity vulnerability due to its potential to allow remote attackers access to sensitive session and cookie information.
To mitigate CVE-2017-4011, ensure that you update McAfee Network Data Loss Prevention to version 9.3.1 or higher.
CVE-2017-4011 affects McAfee Network Data Loss Prevention versions prior to 9.3.1.
CVE-2017-4011 is classified as an embedding script cross-site scripting (XSS) vulnerability.
Yes, CVE-2017-4011 can be remotely exploited, allowing attackers to modify HTTP requests to gain access to session and cookie data.