CVE-2017-4015: Input Validation
Published May 17, 2017
·Updated
Clickjacking vulnerability in the server in McAfee Network Data Loss Prevention (NDLP) 9.3.x allows remote authenticated users to inject arbitrary web script or HTML via HTTP response header.
Affected Software
1 affected component
Mcafee Network Data Loss Prevention<=9.3.0
Event History
May 17, 2017
CVE Published
via MITRE·09:00 PM
Data Sourced
via MITRE·09:00 PM
DescriptionWeakness
Frequently Asked Questions
1
What is the severity of CVE-2017-4015?
CVE-2017-4015 is considered to have a medium severity due to its potential for clickjacking attacks.
2
How do I fix CVE-2017-4015?
To fix CVE-2017-4015, upgrade McAfee Network Data Loss Prevention to version 9.3.1 or later.
3
Who is affected by CVE-2017-4015?
CVE-2017-4015 affects users of McAfee Network Data Loss Prevention version 9.3.x.
4
What kind of vulnerability is CVE-2017-4015?
CVE-2017-4015 is a clickjacking vulnerability that allows for arbitrary web script or HTML injection.
5
Can CVE-2017-4015 be exploited remotely?
Yes, CVE-2017-4015 can be exploited by remote authenticated users.