SQL Injection Vulnerability in McAfee Asset Manager 6.6
CVE-2014-2587
Currently unrated
What is CVE-2014-2587?
A SQL injection vulnerability exists in the ReportsAudit.jsp component of McAfee Asset Manager 6.6. This flaw enables remote authenticated users to manipulate SQL queries by injecting malicious SQL code through the username field in an audit report. This could potentially lead to unauthorized data access or alteration within the database, compromising the integrity of the application.