McAfee Threat Intelligence Exchange (TIE) Server - Code Injection vulnerability
CVE-2017-3907

5.4MEDIUM

Key Information:

Vendor

Mcafee

Vendor
CVE Published:
13 June 2018

What is CVE-2017-3907?

Code Injection vulnerability in the ePolicy Orchestrator (ePO) extension in McAfee Threat Intelligence Exchange (TIE) Server 2.1.0 and earlier allows remote attackers to execute arbitrary HTML code to be reflected in the response web page via unspecified vector.

Affected Version(s)

Threat Intelligence Exchange (TIE) Server x86 2.1.0 < 2.1.0 Hotfix 1

References

CVSS V3.1

Score:
5.4
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2017-3907 : McAfee Threat Intelligence Exchange (TIE) Server - Code Injection vulnerability