First published: Wed May 17 2017(Updated: )
Clickjacking vulnerability in the server in McAfee Network Data Loss Prevention (NDLP) 9.3.x allows remote authenticated users to inject arbitrary web script or HTML via HTTP response header.
Credit: secure@intel.com secure@intel.com
Affected Software | Affected Version | How to fix |
---|---|---|
Mcafee Network Data Loss Prevention | <=9.3.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2017-4015 is considered to have a medium severity due to its potential for clickjacking attacks.
To fix CVE-2017-4015, upgrade McAfee Network Data Loss Prevention to version 9.3.1 or later.
CVE-2017-4015 affects users of McAfee Network Data Loss Prevention version 9.3.x.
CVE-2017-4015 is a clickjacking vulnerability that allows for arbitrary web script or HTML injection.
Yes, CVE-2017-4015 can be exploited by remote authenticated users.