An External XML entity (XXE) vulnerability in ePO prior to 5.10 Update 14 can lead to an unauthenticated remote attacker to potentially trigger a Server Side Request Forgery attack. This can be exploited by mimicking the Agent Handler call to ePO and passing the carefully constructed XML file through the API.
2022-10-18T10:15:10.637
2024-11-21T07:19:19.557
Modified
CVSSv3.1: 5.4 (MEDIUM)
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | mcafee | epolicy_orchestrator | < 5.10.0 | Yes |
Application | mcafee | epolicy_orchestrator | 5.10.0 | Yes |
Application | mcafee | epolicy_orchestrator | 5.10.0 | Yes |
Application | mcafee | epolicy_orchestrator | 5.10.0 | Yes |
Application | mcafee | epolicy_orchestrator | 5.10.0 | Yes |
Application | mcafee | epolicy_orchestrator | 5.10.0 | Yes |
Application | mcafee | epolicy_orchestrator | 5.10.0 | Yes |
Application | mcafee | epolicy_orchestrator | 5.10.0 | Yes |
Application | mcafee | epolicy_orchestrator | 5.10.0 | Yes |
Application | mcafee | epolicy_orchestrator | 5.10.0 | Yes |
Application | mcafee | epolicy_orchestrator | 5.10.0 | Yes |
Application | mcafee | epolicy_orchestrator | 5.10.0 | Yes |
Application | mcafee | epolicy_orchestrator | 5.10.0 | Yes |
Application | mcafee | epolicy_orchestrator | 5.10.0 | Yes |
Application | mcafee | epolicy_orchestrator | 5.10.0 | Yes |