CVE-2015-0921

McAfee ePolicy Orchestrator < 4.6.9 and 5.x < 5.1.2 - Authenticated XML External Entity Injection via Server Task Log

Title source: llm
STIX 2.1

Description

XML external entity (XXE) vulnerability in the Server Task Log in McAfee ePolicy Orchestrator (ePO) before 4.6.9 and 5.x before 5.1.2 allows remote authenticated users to read arbitrary files via the conditionXML parameter to the taskLogTable to orionUpdateTableFilter.do.

References (8)

Core 8
Core References
Mailing List, Third Party Advisory mailing-list x_refsource_fulldisc
http://seclists.org/fulldisclosure/2015/Jan/37
Patch, Vendor Advisory x_refsource_confirm
https://kc.mcafee.com/corporate/index?page=content&id=SB10095
Mailing List, Third Party Advisory mailing-list x_refsource_fulldisc
http://seclists.org/fulldisclosure/2015/Jan/8
Third Party Advisory, VDB Entry vdb-entry x_refsource_sectrack
http://www.securitytracker.com/id/1031519
Third Party Advisory, VDB Entry vdb-entry x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/99950
Third Party Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/61922

Scores

EPSS 0.5822
EPSS Percentile 98.2%

Details

Status published
Products (5)
mcafee/epolicy_orchestrator 5.0.0
mcafee/epolicy_orchestrator 5.0.1
mcafee/epolicy_orchestrator 5.1.0
mcafee/epolicy_orchestrator 5.1.1
mcafee/epolicy_orchestrator < 4.6.8
Published Jan 09, 2015
Tracked Since Feb 18, 2026