CVE-2017-4017: Infoleak
Published May 17, 2017
·Updated
User Name Disclosure in the server in McAfee Network Data Loss Prevention (NDLP) 9.3.x allows remote attackers to view user information via the appliance web interface.
Affected Software
1 affected component
Mcafee Network Data Loss Prevention<=9.3.0
Event History
May 17, 2017
CVE Published
via MITRE·09:00 PM
Data Sourced
via MITRE·09:00 PM
DescriptionWeakness
Frequently Asked Questions
1
What is the severity of CVE-2017-4017?
CVE-2017-4017 is classified as a medium severity vulnerability due to the potential for user information disclosure.
2
How do I fix CVE-2017-4017?
To fix CVE-2017-4017, you should apply the latest security patches and updates provided by McAfee for the Network Data Loss Prevention software.
3
What versions are affected by CVE-2017-4017?
CVE-2017-4017 affects McAfee Network Data Loss Prevention versions up to 9.3.0.
4
What type of vulnerability is CVE-2017-4017?
CVE-2017-4017 is a user name disclosure vulnerability that allows remote attackers to view user information.
5
Is CVE-2017-4017 publicly exploited?
There is currently no evidence suggesting public exploitation of CVE-2017-4017, but remote attacks are possible.