PT-2021-12643 · Mcafee · Mcafee Advanced Threat Defense
Published
2021-04-15
·
Updated
2023-11-16
·
CVE-2020-7269
CVSS v3.1
4.9
Medium
| Vector | AV:A/AC:L/PR:L/UI:R/S:U/C:L/I:L/A:L |
Name of the Vulnerable Software and Affected Versions:
McAfee Advanced Threat Defense (ATD) versions prior to 4.12.2
Description:
The issue allows remote authenticated users to view sensitive unencrypted information via a carefully crafted HTTP request parameter in the web interface. The risk is partially mitigated if the ATD instances are deployed as recommended with no direct access from the Internet to them.
Recommendations:
For versions prior to 4.12.2, update to version 4.12.2 or later to resolve the issue. As a temporary workaround, consider restricting direct access from the Internet to the ATD instances, deploying them as recommended.
Fix
Information Disclosure
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Mcafee Advanced Threat Defense