CVE-2015-0921
McAfee ePolicy Orchestrator < 4.6.9 and 5.x < 5.1.2 - Authenticated XML External Entity Injection via Server Task Log
Title source: llmDescription
XML external entity (XXE) vulnerability in the Server Task Log in McAfee ePolicy Orchestrator (ePO) before 4.6.9 and 5.x before 5.1.2 allows remote authenticated users to read arbitrary files via the conditionXML parameter to the taskLogTable to orionUpdateTableFilter.do.
References (8)
Core 8
Core References
Mailing List, Third Party Advisory mailing-list
x_refsource_fulldisc
http://seclists.org/fulldisclosure/2015/Jan/37
Patch, Vendor Advisory x_refsource_confirm
https://kc.mcafee.com/corporate/index?page=content&id=SB10095
Exploit, Third Party Advisory, VDB Entry x_refsource_misc
http://packetstormsecurity.com/files/129827/McAfee-ePolicy-Orchestrator-Authenticated-XXE-Credential-Exposure.html
Mailing List, Third Party Advisory mailing-list
x_refsource_fulldisc
http://seclists.org/fulldisclosure/2015/Jan/8
Third Party Advisory, VDB Entry vdb-entry
x_refsource_sectrack
http://www.securitytracker.com/id/1031519
Various Sources x_refsource_misc
https://gist.github.com/brandonprry/692e553975bf29aeaf2c
Third Party Advisory, VDB Entry vdb-entry
x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/99950
Third Party Advisory third-party-advisory
x_refsource_secunia
http://secunia.com/advisories/61922
Scores
EPSS
0.5822
EPSS Percentile
98.2%
Details
Status
published
Products (5)
mcafee/epolicy_orchestrator
5.0.0
mcafee/epolicy_orchestrator
5.0.1
mcafee/epolicy_orchestrator
5.1.0
mcafee/epolicy_orchestrator
5.1.1
mcafee/epolicy_orchestrator
< 4.6.8
Published
Jan 09, 2015
Tracked Since
Feb 18, 2026