PT-2005-3116 · Mcafee · Mcafee Intrushield Security Management System
C0Ntexb
·
Published
2005-07-10
·
Updated
2016-10-18
·
CVE-2005-2187
CVSS v2.0
4.6
Medium
| Vector | AV:L/AC:L/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions:
McAfee IntruShield Security Management System (affected versions not specified)
Description:
The issue allows remote authenticated users to access the "Generate Reports" feature and modify alerts by setting the Access option to true. This can be achieved by manipulating specific parameters in certain JSP files, including setting the
fullAccess or fullAccessRight parameter in "reports-column-center.jsp", or the fullAccess parameter in "SystemEvent.jsp".Recommendations:
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Mcafee Intrushield Security Management System