First published: Wed Aug 14 2019(Updated: )
Exfiltration of Data in McAfee Web Gateway (MWG) 7.8.2.x prior to 7.8.2.12 allows attackers to obtain sensitive data via crafting a complex webpage that will trigger the Web Gateway to block the user accessing an iframe.
Credit: psirt@mcafee.com
Affected Software | Affected Version | How to fix |
---|---|---|
McAfee Web Gateway | >=7.8.2.0<7.8.2.12 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2019-3635 is a vulnerability in McAfee Web Gateway (MWG) 7.8.2.x prior to 7.8.2.12 that allows attackers to obtain sensitive data via crafting a complex webpage.
CVE-2019-3635 works by crafting a complex webpage that triggers the Web Gateway to block the user accessing an iframe, allowing attackers to exfiltrate sensitive data.
The severity of CVE-2019-3635 is medium with a severity value of 6.5.
McAfee Web Gateway (MWG) 7.8.2.x prior to 7.8.2.12 is affected by CVE-2019-3635.
To fix CVE-2019-3635, update McAfee Web Gateway to version 7.8.2.12 or newer.