PT-2022-13466 · Mcafee · Mcafee Enterprise Epolicy Orchestrator

Published

2022-03-23

·

Updated

2023-11-15

·

CVE-2022-0842

CVSS v3.1

5.4

Medium

VectorAV:N/AC:H/PR:H/UI:R/S:C/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions McAfee Enterprise ePolicy Orchestrator versions prior to 5.10 Update 13
Description A blind SQL injection issue allows a remote authenticated attacker to potentially obtain information from the database, with the data obtained being dependent on the attacker's privileges. To obtain sensitive data, the attacker would require administrator privileges.
Recommendations For versions prior to 5.10 Update 13, update to version 5.10 Update 13 or later to resolve the issue. As a temporary workaround, consider restricting access to the database and limiting user privileges to minimize the risk of exploitation.

Fix

SQL injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2022-0842

Affected Products

Mcafee Enterprise Epolicy Orchestrator