Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-gjcx-3wpq-4ph2

Опубликовано: 24 мар. 2022
Источник: github
Github: Не прошло ревью
CVSS3: 4.9

Описание

A blind SQL injection vulnerability in McAfee Enterprise ePolicy Orchestrator (ePO) prior to 5.10 Update 13 allows a remote authenticated attacker to potentially obtain information from the ePO database. The data obtained is dependent on the privileges the attacker has and to obtain sensitive data the attacker would require administrator privileges.

A blind SQL injection vulnerability in McAfee Enterprise ePolicy Orchestrator (ePO) prior to 5.10 Update 13 allows a remote authenticated attacker to potentially obtain information from the ePO database. The data obtained is dependent on the privileges the attacker has and to obtain sensitive data the attacker would require administrator privileges.

EPSS

Процентиль: 37%
0.00156
Низкий

4.9 Medium

CVSS3

Дефекты

CWE-89

Связанные уязвимости

CVSS3: 5.4
nvd
почти 4 года назад

A blind SQL injection vulnerability in McAfee Enterprise ePolicy Orchestrator (ePO) prior to 5.10 Update 13 allows a remote authenticated attacker to potentially obtain information from the ePO database. The data obtained is dependent on the privileges the attacker has and to obtain sensitive data the attacker would require administrator privileges.

EPSS

Процентиль: 37%
0.00156
Низкий

4.9 Medium

CVSS3

Дефекты

CWE-89