Session fixation vulnerability in the web interface in McAfee Network Security Manager (NSM) before 8.2.7.42.2 and McAfee Network Data Loss Prevention (NDLP) before 9.3.4.1.5 allows remote attackers to disclose sensitive information or manipulate the database via a crafted authentication cookie.
References
Link | Resource |
---|---|
https://kc.mcafee.com/corporate/index?page=content&id=SB10198 | Vendor Advisory |
https://kc.mcafee.com/corporate/index?page=content&id=SB10192 | Vendor Advisory |
Configurations
Configuration 1 (hide)
|
Information
Published : 2018-06-13 13:29
Updated : 2019-10-09 16:27
NVD link : CVE-2017-3968
Mitre link : CVE-2017-3968
JSON object : View
CWE
CWE-384
Session Fixation
Products Affected
mcafee
- network_security_manager
- network_data_loss_prevention