PT-2021-4989 · Mcafee · Mcafee Policy Auditor

Published

2021-11-22

·

Updated

2023-11-21

·

CVE-2021-31852

CVSS v2.0

6.4

Medium

VectorAV:N/AC:L/Au:N/C:P/I:P/A:N
Name of the Vulnerable Software and Affected Versions McAfee Policy Auditor versions prior to 6.5.2
Description The issue is related to a Reflected Cross-Site Scripting vulnerability in the web interface of McAfee Policy Auditor. This vulnerability allows a remote unauthenticated attacker to inject arbitrary web script or HTML via the UID request parameter. The malicious script is reflected unmodified into the Policy Auditor web-based interface, which could lead to the extraction of end-user session tokens or login credentials. These may be used to access additional security-critical applications or conduct arbitrary cross-domain requests.
Recommendations For McAfee Policy Auditor versions prior to 6.5.2, update to version 6.5.2 or later to resolve the issue. As a temporary workaround, consider restricting access to the vulnerable web interface until a patch is applied. Avoid using the UID parameter in the affected API endpoint until the issue is resolved.

Fix

XSS

Weakness Enumeration

Related Identifiers

BDU:2021-05752
CVE-2021-31852

Affected Products

Mcafee Policy Auditor