First published: Thu Sep 12 2019(Updated: )
Reflected Cross Site Scripting vulnerability in Administrators web console in McAfee Web Gateway (MWG) 7.8.x prior to 7.8.2.13 allows remote attackers to collect sensitive information or execute commands with the MWG administrator's credentials via tricking the administrator to click on a carefully constructed malicious link.
Credit: psirt@mcafee.com
Affected Software | Affected Version | How to fix |
---|---|---|
McAfee Web Gateway | >=7.8.2<7.8.2.13 | |
McAfee Web Gateway | >=8.0.0<8.2.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2019-3638 is a Reflected Cross Site Scripting vulnerability in the Administrators web console in McAfee Web Gateway (MWG) 7.8.x prior to 7.8.2.13.
CVE-2019-3638 allows remote attackers to collect sensitive information or execute commands with the MWG administrator's credentials by tricking the administrator into clicking on a carefully crafted link.
CVE-2019-3638 is classified as critical with a severity value of 9.6.
McAfee Web Gateway versions 7.8.x prior to 7.8.2.13 and versions 8.0.0 to 8.2.0 are affected by CVE-2019-3638.
To fix CVE-2019-3638, it is recommended to upgrade to McAfee Web Gateway version 7.8.2.13 or later.