Command Injection vulnerability in McAfee Enterprise Security Manager (ESM) prior to 11.2.0 and prior to 10.4.0 allows authenticated user to execute arbitrary code via specially crafted parameters.
2019-06-27T21:15:10.450
2024-11-21T04:42:15.817
Modified
CVSSv3.1: 7.2 (HIGH)
AV:N/AC:L/Au:S/C:P/I:P/A:P
8.0
6.4
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | mcafee | enterprise_security_manager | < 10.4.0 | Yes |
Application | mcafee | enterprise_security_manager | < 11.2.0 | Yes |