CVE-2019-3665: Code Injection vulnerability
Code Injection vulnerability in the web interface in McAfee Web Advisor (WA) prior to 4.1.1.48 allows remote unauthenticated attacker to allow the browser to render a website which Web Advisor would normally have blocked via a carefully crafted web site.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2019-3665?
The severity of CVE-2019-3665 is medium with a severity value of 6.5.
How does CVE-2019-3665 affect McAfee Web Advisor?
CVE-2019-3665 affects McAfee Web Advisor prior to version 4.1.1.48 by allowing remote unauthenticated attackers to bypass website blocking.
How can I fix the Code Injection vulnerability in McAfee Web Advisor CVE-2019-3665?
To fix the Code Injection vulnerability in McAfee Web Advisor CVE-2019-3665, upgrade to version 4.1.1.48 or later.
What is the Common Weakness Enumeration (CWE) ID for CVE-2019-3665?
The Common Weakness Enumeration (CWE) ID for CVE-2019-3665 is 94.
Where can I find more information about CVE-2019-3665?
You can find more information about CVE-2019-3665 in McAfee's FAQ document: http://service.mcafee.com/FAQDocument.aspx?&id=TS102991