A XML Extended entity vulnerability in McAfee Enterprise ePolicy Orchestrator (ePO) prior to 5.10 Update 13 allows a remote administrator attacker to upload a malicious XML file through the extension import functionality. The impact is limited to some access to confidential information and some ability to alter data.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2022-15903 | A XML Extended entity vulnerability in McAfee Enterprise ePolicy Orchestrator (ePO) prior to 5.10 Update 13 allows a remote administrator attacker to upload a malicious XML file through the extension import functionality. The impact is limited to some access to confidential information and some ability to alter data. |
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
No history.
Status: PUBLISHED
Assigner: trellix
Published:
Updated: 2024-08-02T23:40:04.557Z
Reserved: 2022-03-04T00:00:00.000Z
Link: CVE-2022-0861
No data.
Status : Modified
Published: 2022-03-23T15:15:08.557
Modified: 2024-11-21T06:39:32.967
Link: CVE-2022-0861
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD