PT-2018-7318 · Mcafee · Mcafee Network Data Loss Prevention+1
Publicado
2018-06-13
·
Atualizado
2019-10-09
·
CVE-2017-3968
CVSS v3.1
9.1
Crítica
| Vetor | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N |
Name of the Vulnerable Software and Affected Versions:
McAfee Network Security Manager (NSM) versions prior to 8.2.7.42.2
McAfee Network Data Loss Prevention (NDLP) versions prior to 9.3.4.1.5
Description:
A session fixation issue in the web interface allows remote attackers to disclose sensitive information or manipulate the database via a crafted authentication cookie.
Recommendations:
For McAfee Network Security Manager (NSM) versions prior to 8.2.7.42.2, update to version 8.2.7.42.2 or later.
For McAfee Network Data Loss Prevention (NDLP) versions prior to 9.3.4.1.5, update to version 9.3.4.1.5 or later.
Correção
Session Fixation
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Mcafee Network Data Loss Prevention
Mcafee Network Security Management