CVE-2017-4014: High severity Mcafee Network Data Loss Prevention vulnerability
Published May 17, 2017
·Updated
Session Side jacking vulnerability in the server in McAfee Network Data Loss Prevention (NDLP) 9.3.x allows remote authenticated users to view, add, and remove users via modification of the HTTP request.
Affected Software
1 affected component
Mcafee Network Data Loss Prevention<=9.3.0
Event History
May 17, 2017
CVE Published
via MITRE·09:00 PM
Data Sourced
via MITRE·09:00 PM
DescriptionWeakness
Frequently Asked Questions
1
What is the severity of CVE-2017-4014?
CVE-2017-4014 has a medium severity level due to its ability to allow unauthorized user management.
2
How do I fix CVE-2017-4014?
To fix CVE-2017-4014, update to McAfee Network Data Loss Prevention version 9.3.1 or later.
3
Who is affected by CVE-2017-4014?
CVE-2017-4014 affects users of McAfee Network Data Loss Prevention versions 9.3.0 and earlier.
4
What types of attacks can CVE-2017-4014 facilitate?
CVE-2017-4014 can facilitate session hijacking, allowing remote authenticated users to manipulate users within the system.
5
Is CVE-2017-4014 a client-side or server-side vulnerability?
CVE-2017-4014 is a server-side vulnerability that affects how user management is handled.