CVE-2021-31849: Data Loss Prevention (DLP) ePO extension - SQL injection
SQL injection vulnerability in McAfee Data Loss Prevention (DLP) ePO extension prior to 11.7.100 allows a remote attacker logged into ePO as an administrator to inject arbitrary SQL into the ePO database through the user management section of the DLP ePO extension.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2021-31849?
The severity of CVE-2021-31849 is high.
How does CVE-2021-31849 affect McAfee Data Loss Prevention (DLP) ePO extension?
CVE-2021-31849 allows a remote attacker logged into ePO as an administrator to inject arbitrary SQL into the ePO database through the user management section of the DLP ePO extension.
Which versions of McAfee Data Loss Prevention Endpoint are affected by CVE-2021-31849?
McAfee Data Loss Prevention Endpoint versions between 11.6.0 and 11.6.400, as well as versions between 11.7.0 and 11.7.100 are affected by CVE-2021-31849.
How can I fix CVE-2021-31849?
To fix CVE-2021-31849, it is recommended to update McAfee Data Loss Prevention (DLP) ePO extension to version 11.7.100 or later.
Where can I find more information about CVE-2021-31849?
You can find more information about CVE-2021-31849 on the McAfee Knowledge Center website: https://kc.mcafee.com/corporate/index?page=content&id=SB10371