CVE-2019-3619: Medium severity mcafee epolicy orchestrator vulnerability
Information Disclosure vulnerability in the Agent Handler in McAfee ePolicy Orchestrator (ePO) 5.9.x and 5.10.0 prior to 5.10.0 update 4 allows remote unauthenticated attacker to view sensitive information in plain text via sniffing the traffic between the Agent Handler and the SQL server.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2019-3619?
CVE-2019-3619 is an information disclosure vulnerability in the Agent Handler in McAfee ePolicy Orchestrator (ePO) 5.9.x and 5.10.0 prior to 5.10.0 update 4.
How does CVE-2019-3619 affect McAfee ePolicy Orchestrator?
CVE-2019-3619 allows a remote unauthenticated attacker to view sensitive information in plain text by sniffing the traffic between the Agent Handler and the SQL server.
What is the severity of CVE-2019-3619?
CVE-2019-3619 has a severity rating of 4.9 (medium).
Which versions of McAfee ePolicy Orchestrator are affected by CVE-2019-3619?
CVE-2019-3619 affects McAfee ePolicy Orchestrator versions 5.9.0, 5.9.1, 5.10.0, 5.10.0-update_1, 5.10.0-update_2, and 5.10.0-update_3.
How can I fix CVE-2019-3619?
To fix CVE-2019-3619, it is recommended to update McAfee ePolicy Orchestrator to version 5.10.0 update 4 or later.