PT-2019-4249 · Mcafee · Mcafee Advanced Threat Defense

Publicado

2019-11-12

·

Atualizado

2019-11-15

·

CVE-2019-3662

CVSS v2.0

6.8

Média

VetorAV:N/AC:L/Au:S/C:C/I:N/A:N
Name of the Vulnerable Software and Affected Versions McAfee Advanced Threat Defense versions prior to 4.8
Description The issue allows a remote authenticated attacker to gain unintended access to files on the system via carefully constructed HTTP requests. This is due to incorrect restriction of the pathname to a directory with limited access. The vulnerability can be exploited by sending specially formed HTTP requests, potentially giving an attacker access to files in the local file system.
Recommendations For versions prior to 4.8, update to version 4.8 or later to resolve the issue. As a temporary workaround, consider restricting access to sensitive files and directories to minimize the risk of exploitation. Avoid using the /absolute/pathname/here endpoint in HTTP requests until the issue is resolved.

Correção

Path traversal

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

BDU:2019-04850
CVE-2019-3662

Produtos afetados

Mcafee Advanced Threat Defense