OS Command Injection vulnerability in McAfee ePolicy Orchestrator (ePO) 5.9.0, 5.3.2, 5.3.1, 5.1.3, 5.1.2, 5.1.1, and 5.1.0 allows attackers to run arbitrary OS commands with limited privileges via not sanitizing the user input data before exporting it into a CSV format output.
References
Link | Resource |
---|---|
https://kc.mcafee.com/corporate/index?page=content&id=SB10227 | Vendor Advisory |
http://www.securityfocus.com/bid/103155 | Third Party Advisory VDB Entry |
Configurations
Configuration 1 (hide)
|
Information
Published : 2018-06-13 14:29
Updated : 2019-10-09 16:27
NVD link : CVE-2017-3936
Mitre link : CVE-2017-3936
JSON object : View
CWE
CWE-78
Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
Products Affected
mcafee
- epolicy_orchestrator