PT-2020-19536 · Mcafee · Mcafee Data Loss Prevention (Dlp) Epo Extension

Published

2020-08-12

·

Updated

2022-07-01

·

CVE-2020-7300

CVSS v3.1

6.3

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L
Name of the Vulnerable Software and Affected Versions McAfee Data Loss Prevention (DLP) ePO extension versions prior to 11.5.3
Description The issue allows authenticated remote attackers to change the configuration when logged in with view-only privileges via carefully constructed HTTP post messages. This is due to an improper authorization vulnerability.
Recommendations For versions prior to 11.5.3, update to version 11.5.3 or later to resolve the issue. As a temporary workaround, consider restricting access to the configuration settings to prevent unauthorized changes until the update is applied.

Fix

Incorrect Authorization

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2020-7300

Affected Products

Mcafee Data Loss Prevention (Dlp) Epo Extension