CVE-2017-4015

MEDIUM

McAfee Network Data Loss Prevention 9.3.x - Authenticated Clickjacking via HTTP Response Header

Title source: llm
STIX 2.1

Description

Clickjacking vulnerability in the server in McAfee Network Data Loss Prevention (NDLP) 9.3.x allows remote authenticated users to inject arbitrary web script or HTML via HTTP response header.

References (2)

Core 2
Core References
Broken Link, Vendor Advisory x_refsource_confirm
https://kc.mcafee.com/corporate/index?page=content&id=SB10198
Broken Link, Third Party Advisory, VDB Entry vdb-entry x_refsource_sectrack
http://www.securitytracker.com/id/1038523

Scores

CVSS v3 4.5
EPSS 0.0022
EPSS Percentile 44.9%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:N/I:H/A:N

Details

CWE
CWE-1021
Status published
Products (2)
McAfee/Network Data Loss Prevention (NDLP) 9.3.x
mcafee/network_data_loss_prevention < 9.3.0
Published May 17, 2017
Tracked Since Feb 18, 2026