CVE-2019-3641

MEDIUM

McAfee Threat Intelligence Exchange Server 3.0.0 - Authenticated Reputation Data Modification via API

Title source: llm
STIX 2.1

Description

Abuse of Authorization vulnerability in APIs exposed by TIE server in McAfee Threat Intelligence Exchange Server (TIE Server) 3.0.0 allows remote authenticated users to modify stored reputation data via specially crafted messages.

References (1)

Core 1
Core References

Scores

CVSS v3 4.5
EPSS 0.0023
EPSS Percentile 46.0%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:N/I:H/A:N

Details

CWE
CWE-285
Status published
Products (1)
mcafee/threat_intelligence_exchange_server 3.0.0
Published Nov 13, 2019
Tracked Since Feb 18, 2026