PT-2019-4249 · Mcafee · Mcafee Advanced Threat Defense

Published

2019-11-12

·

Updated

2019-11-15

·

CVE-2019-3662

CVSS v2.0

6.8

Medium

VectorAV:N/AC:L/Au:S/C:C/I:N/A:N
Name of the Vulnerable Software and Affected Versions McAfee Advanced Threat Defense versions prior to 4.8
Description The issue allows a remote authenticated attacker to gain unintended access to files on the system via carefully constructed HTTP requests. This is due to incorrect restriction of the pathname to a directory with limited access. The vulnerability can be exploited by sending specially formed HTTP requests, potentially giving an attacker access to files in the local file system.
Recommendations For versions prior to 4.8, update to version 4.8 or later to resolve the issue. As a temporary workaround, consider restricting access to sensitive files and directories to minimize the risk of exploitation. Avoid using the /absolute/pathname/here endpoint in HTTP requests until the issue is resolved.

Fix

Path traversal

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2019-04850
CVE-2019-3662

Affected Products

Mcafee Advanced Threat Defense