ZeroHour

CVE-2022-0861

CVSS 3.1
3.8 low
EPSS
<1%p39
Published
()
Modified
Description

A XML Extended entity vulnerability in McAfee Enterprise ePolicy Orchestrator (ePO) prior to 5.10 Update 13 allows a remote administrator attacker to upload a malicious XML file through the extension import functionality. The impact is limited to some access to confidential information and some ability to alter data.

Vendors
mcafee
Products
epolicy orchestrator
Weakness
CWE-611
Vector
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:L/A:N

In the news

No ingested article mentions this CVE yet.