CVE-2019-3650: Advanced Threat Defense (ATD) - Information Disclosure vulnerability
Information Disclosure vulnerability in McAfee Advanced Threat Defense (ATD prior to 4.8 allows remote authenticated attackers to gain access to the atduser credentials via carefully constructed GET request extracting insecurely information stored in the database.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2019-3650?
CVE-2019-3650 is an information disclosure vulnerability in McAfee Advanced Threat Defense (ATD) prior to version 4.8.
How does CVE-2019-3650 impact the system?
CVE-2019-3650 allows remote authenticated attackers to gain access to the atduser credentials by exploiting a carefully constructed GET request and extracting insecurely stored information in the database.
What is the severity of CVE-2019-3650?
The severity of CVE-2019-3650 is medium with a CVSS score of 6.5.
How can I fix CVE-2019-3650?
To fix CVE-2019-3650, update McAfee Advanced Threat Defense to version 4.8 or later.
Where can I find more information about CVE-2019-3650?
More information about CVE-2019-3650 can be found on the official McAfee Knowledge Center at https://kc.mcafee.com/corporate/index?page=content&id=SB10304.