PT-2005-3116 · Mcafee · Mcafee Intrushield Security Management System

C0Ntexb

·

Publicado

2005-07-10

·

Atualizado

2016-10-18

·

CVE-2005-2187

CVSS v2.0

4.6

Média

VetorAV:L/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions: McAfee IntruShield Security Management System (affected versions not specified)
Description: The issue allows remote authenticated users to access the "Generate Reports" feature and modify alerts by setting the Access option to true. This can be achieved by manipulating specific parameters in certain JSP files, including setting the fullAccess or fullAccessRight parameter in "reports-column-center.jsp", or the fullAccess parameter in "SystemEvent.jsp".
Recommendations: At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Identificadores relacionados

CVE-2005-2187

Produtos afetados

Mcafee Intrushield Security Management System