First published: Wed Mar 23 2022(Updated: )
A XML Extended entity vulnerability in McAfee Enterprise ePolicy Orchestrator (ePO) prior to 5.10 Update 13 allows a remote administrator attacker to upload a malicious XML file through the extension import functionality. The impact is limited to some access to confidential information and some ability to alter data.
Credit: psirt@mcafee.com trellixpsirt@trellix.com
Affected Software | Affected Version | How to fix |
---|---|---|
McAfee ePolicy Orchestrator | <5.10.0 | |
McAfee ePolicy Orchestrator | =5.10.0 | |
McAfee ePolicy Orchestrator | =5.10.0-update_1 | |
McAfee ePolicy Orchestrator | =5.10.0-update_10 | |
McAfee ePolicy Orchestrator | =5.10.0-update_11 | |
McAfee ePolicy Orchestrator | =5.10.0-update_12 | |
McAfee ePolicy Orchestrator | =5.10.0-update_2 | |
McAfee ePolicy Orchestrator | =5.10.0-update_3 | |
McAfee ePolicy Orchestrator | =5.10.0-update_4 | |
McAfee ePolicy Orchestrator | =5.10.0-update_5 | |
McAfee ePolicy Orchestrator | =5.10.0-update_6 | |
McAfee ePolicy Orchestrator | =5.10.0-update_7 | |
McAfee ePolicy Orchestrator | =5.10.0-update_8 | |
McAfee ePolicy Orchestrator | =5.10.0-update_9 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2022-0861 is a XML Extended entity vulnerability in McAfee Enterprise ePolicy Orchestrator (ePO) prior to 5.10 Update 13.
CVE-2022-0861 allows a remote administrator attacker to upload a malicious XML file through the extension import functionality, causing limited access to confidential information and some ability to perform unauthorized actions.
CVE-2022-0861 has a severity rating of 3.8, which is considered medium.
To fix CVE-2022-0861, you need to update your McAfee Enterprise ePolicy Orchestrator (ePO) to version 5.10 Update 13 or later.
You can find more information about CVE-2022-0861 on the McAfee website at the following link: [CVE-2022-0861](https://kc.mcafee.com/corporate/index?page=content&id=SB10379)