PT-2014-8587 · Mcafee · Mcafee Network Data Loss Prevention

Published

2014-10-29

·

Updated

2014-10-30

·

CVE-2014-8524

CVSS v2.0

5.0

Medium

VectorAV:N/AC:L/Au:N/C:P/I:N/A:N
Name of the Vulnerable Software and Affected Versions McAfee Network Data Loss Prevention (NDLP) versions prior to 9.3
Description The issue allows remote attackers to obtain sensitive information via unspecified vectors because the autocomplete setting for the password and other fields is not disabled.
Recommendations For versions prior to 9.3, update to version 9.3 or later to resolve the issue. As a temporary workaround, consider disabling the autocomplete feature for sensitive fields until a patch is available.

Fix

Information Disclosure

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2014-8524

Affected Products

Mcafee Network Data Loss Prevention