SQL injection vulnerability in core services in Intel Security McAfee ePolicy Orchestrator (ePO) 5.3.2 and earlier and 5.1.3 and earlier allows attackers to alter a SQL query, which can result in disclosure of information within the database or impersonation of an agent without authentication via a specially crafted HTTP post.
2017-03-14T22:59:01.197
2025-04-20T01:37:25.860
Deferred
CVSSv3.0: 10.0 (CRITICAL)
AV:N/AC:L/Au:N/C:P/I:P/A:P
10.0
6.4
| Type | Vendor | Product | Version/Range | Vulnerable? |
|---|---|---|---|---|
| Application | mcafee | epolicy_orchestrator | ≤ 5.1.3 | Yes |
| Application | mcafee | epolicy_orchestrator | ≤ 5.3.2 | Yes |