Check: 2017-A-0036
Windows 2012 IAVM:
2017-A-0036
(in version v1 r30)
Title
Multiple Vulnerabilities in McAfee ePolicy Orchestrator (Cat I impact)
Discussion
McAfee has released a security bulletin addressing multiple vulnerabilities in ePolicy Orchestrator. McAfee ePolicy Orchestrator (ePO) supports integration with external registered servers for a variety of purposes, such as data collection and aggregation. To exploit these vulnerabilities, an attacker could submit malicious input data containing properly formatted SQL syntax to the affected application through the affected parameter. If successfully exploited, these vulnerabilities would allow an attacker to cause a denial of service condition, gain unauthorized access, and execute arbitrary code in the context of the affected application.
Check Content
Fix Text
Additional Identifiers
Rule ID:
Vulnerability ID: V-73915
Group Title:
Expert Comments
CCIs
Number | Definition |
---|---|
No CCIs are assigned to this check |
Controls
Number | Title |
---|---|
No controls are assigned to this check |