SQL Injection Vulnerability in Intel Security McAfee ePolicy Orchestrator
CVE-2016-8027
Key Information:
- Vendor
- Mcafee
- Vendor
- CVE Published:
- 14 March 2017
Summary
An SQL injection vulnerability exists in core services of Intel Security's McAfee ePolicy Orchestrator versions 5.3.2 and earlier, as well as 5.1.3 and earlier. This flaw allows attackers to craft specific HTTP requests that alter SQL queries, potentially leading to unauthorized database access or agent impersonation without proper authentication. Attackers exploiting this vulnerability can gain unauthorized insights into sensitive database information, posing significant risks to organizations relying on this service.
Affected Version(s)
McAfee ePolicy Orchestrator (ePO) 5.3.2 and earlier and 5.1.3 and earlier McAfee ePolicy Orchestrator (ePO) 5.3.2 and earlier and 5.1.3 and earlier
References
EPSS Score
16% chance of being exploited in the next 30 days.
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved