PT-2022-13477 · Mcafee · Mcafee Enterprise Epolicy Orchestrator

Published

2022-03-23

·

Updated

2023-11-16

·

CVE-2022-0858

CVSS v3.1

4.7

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:C/C:N/I:L/A:N
Name of the Vulnerable Software and Affected Versions McAfee Enterprise ePolicy Orchestrator versions prior to 5.10 Update 13
Description A cross-site scripting (XSS) issue allows a remote attacker to potentially obtain access to an ePO administrator's session by convincing the attacker to click on a carefully crafted link, leading to limited ability to alter some information in ePO due to the area of the User Interface the issue is present in.
Recommendations For versions prior to 5.10 Update 13, update to version 5.10 Update 13 or later to resolve the issue.

Fix

XSS

Weakness Enumeration

Related Identifiers

CVE-2022-0858

Affected Products

Mcafee Enterprise Epolicy Orchestrator