First published: Mon Nov 01 2021(Updated: )
SQL injection vulnerability in McAfee Data Loss Prevention (DLP) ePO extension prior to 11.7.100 allows a remote attacker logged into ePO as an administrator to inject arbitrary SQL into the ePO database through the user management section of the DLP ePO extension.
Credit: psirt@mcafee.com trellixpsirt@trellix.com
Affected Software | Affected Version | How to fix |
---|---|---|
Mcafee Data Loss Prevention Endpoint | >=11.6.0<11.6.400 | |
Mcafee Data Loss Prevention Endpoint | >=11.7.0<11.7.100 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2021-31849 is high.
CVE-2021-31849 allows a remote attacker logged into ePO as an administrator to inject arbitrary SQL into the ePO database through the user management section of the DLP ePO extension.
McAfee Data Loss Prevention Endpoint versions between 11.6.0 and 11.6.400, as well as versions between 11.7.0 and 11.7.100 are affected by CVE-2021-31849.
To fix CVE-2021-31849, it is recommended to update McAfee Data Loss Prevention (DLP) ePO extension to version 11.7.100 or later.
You can find more information about CVE-2021-31849 on the McAfee Knowledge Center website: https://kc.mcafee.com/corporate/index?page=content&id=SB10371