CVE-2019-3638: Web Gateway (MWG) - Reflected Cross Site Scripting vulnerability
Reflected Cross Site Scripting vulnerability in Administrators web console in McAfee Web Gateway (MWG) 7.8.x prior to 7.8.2.13 allows remote attackers to collect sensitive information or execute commands with the MWG administrator's credentials via tricking the administrator to click on a carefully constructed malicious link.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2019-3638?
CVE-2019-3638 is a Reflected Cross Site Scripting vulnerability in the Administrators web console in McAfee Web Gateway (MWG) 7.8.x prior to 7.8.2.13.
How does CVE-2019-3638 impact McAfee Web Gateway?
CVE-2019-3638 allows remote attackers to collect sensitive information or execute commands with the MWG administrator's credentials by tricking the administrator into clicking on a carefully crafted link.
What is the severity of CVE-2019-3638?
CVE-2019-3638 is classified as critical with a severity value of 9.6.
Which versions of McAfee Web Gateway are affected by CVE-2019-3638?
McAfee Web Gateway versions 7.8.x prior to 7.8.2.13 and versions 8.0.0 to 8.2.0 are affected by CVE-2019-3638.
How can I fix CVE-2019-3638 in McAfee Web Gateway?
To fix CVE-2019-3638, it is recommended to upgrade to McAfee Web Gateway version 7.8.2.13 or later.