First published: Tue Mar 12 2019(Updated: )
Data Leakage Attacks vulnerability in the web interface in McAfee Database Security prior to the 4.6.6 March 2019 update allows local users to expose passwords via incorrectly auto completing password fields in the admin browser login screen.
Credit: psirt@mcafee.com trellixpsirt@trellix.com
Affected Software | Affected Version | How to fix |
---|---|---|
McAfee Database Security | <=4.6.6 | |
<=4.6.6 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID is CVE-2019-3615.
The title of the vulnerability is 'Data Leakage Attacks vulnerability in the web interface in McAfee Database Security prior to the 4.6.6 March 2019 update allows local users to expose passwords via incorrectly auto completing password fields in the admin browser login screen.'
The severity of CVE-2019-3615 is medium.
McAfee Database Security prior to the 4.6.6 March 2019 update is affected by CVE-2019-3615.
Local users can expose passwords in McAfee Database Security due to CVE-2019-3615 by incorrectly auto completing password fields in the admin browser login screen.