McAfee Email and Web Security (EWS) 5.x before 5.5 Patch 6 and 5.6 before Patch 3, and McAfee Email Gateway (MEG) 7.0 before Patch 1, allows remote authenticated users to obtain the session tokens of arbitrary users by navigating within the Dashboard.
2012-08-22T10:42:04.820
2025-04-11T00:51:21.963
Deferred
CVSSv2: 4.0 (MEDIUM)
AV:N/AC:L/Au:S/C:P/I:N/A:N
8.0
2.9
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | mcafee | email_and_web_security | 5.0 | Yes |
Application | mcafee | email_and_web_security | 5.5 | Yes |
Application | mcafee | email_and_web_security | 5.6 | Yes |
Application | mcafee | email_gateway | 7.0 | Yes |