CVE-2017-4014

HIGH

McAfee Network Data Loss Prevention 9.3.x - Authenticated Session Fixation via HTTP Request Modification

Title source: llm
STIX 2.1

Description

Session Side jacking vulnerability in the server in McAfee Network Data Loss Prevention (NDLP) 9.3.x allows remote authenticated users to view, add, and remove users via modification of the HTTP request.

References (2)

Core 2
Core References
Third Party Advisory, VDB Entry vdb-entry x_refsource_sectrack
http://www.securitytracker.com/id/1038523

Scores

CVSS v3 8.0
EPSS 0.0040
EPSS Percentile 60.9%
Attack Vector NETWORK
CVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H

Details

CWE
CWE-384
Status published
Products (2)
McAfee/Network Data Loss Prevention (NDLP) 9.3.x
mcafee/network_data_loss_prevention < 9.3.0
Published May 17, 2017
Tracked Since Feb 18, 2026