CVE-2019-3629: Application protections bypass vulnerability could allow unauthenticated user to impersonate system users
Published Jun 27, 2019
·Updated
Application protection bypass vulnerability in McAfee Enterprise Security Manager (ESM) prior to 11.2.0 and prior to 10.4.0 allows unauthenticated user to impersonate system users via specially crafted parameters.
Affected Software
2 affected components
McAfee Enterprise Security Manager<10.4.0
McAfee Enterprise Security Manager>=11.0.0<11.2.0
Event History
Jun 27, 2019
CVE Published
via MITRE·08:33 PM
Data Sourced
via MITRE·08:33 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the vulnerability ID?
The vulnerability ID is CVE-2019-3629.
2
What is the title of the vulnerability?
The title of the vulnerability is 'Application protection bypass vulnerability in McAfee Enterprise Security Manager (ESM) prior to 11.2.0 and prior to 10.4.0.'
3
What is the severity of CVE-2019-3629?
The severity of CVE-2019-3629 is high with a severity value of 6.5.
4
Which versions of McAfee Enterprise Security Manager are affected by CVE-2019-3629?
McAfee Enterprise Security Manager versions prior to 11.2.0 and prior to 10.4.0 are affected by CVE-2019-3629.
5
How can an unauthenticated user exploit CVE-2019-3629?
An unauthenticated user can exploit CVE-2019-3629 by impersonating system users using specially crafted parameters.