Skip to main content

Vendor/product archive

mcafee / epolicy_orchestrator CVEs

Beta · best-effort

84 CVEs tagged to mcafee / epolicy_orchestrator4 Critical, 14 High, 45 Medium, 21 Low, 0 Unrated.

CVE-2023-5445

Published Nov 17, 2023

An open redirect vulnerability in ePolicy Orchestrator prior to 5.10.0 CP1 Update 2, allows a remote low privileged user to modify the URL parameter for the purpose of redirecting…

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-5444

Published Nov 17, 2023

A Cross Site Request Forgery vulnerability in ePolicy Orchestrator prior to 5.10.0 CP1 Update 2 allows a remote low privilege user to successfully add a new user with administrato…

CVSS 8.0 · High
Vendor/product tagsBeta · best-effort

CVE-2023-3946

Published Jul 26, 2023

A reflected cross-site scripting (XSS) vulnerability in ePO prior to 5.10 SP1 Update 1allows a remote unauthenticated attacker to potentially obtain access to an ePO administrator…

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-3339

Published Oct 18, 2022

A reflected cross-site scripting (XSS) vulnerability in ePO prior to 5.10 Update 14 allows a remote unauthenticated attacker to potentially obtain access to an ePO administrator's…

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-3338

Published Oct 18, 2022

An External XML entity (XXE) vulnerability in ePO prior to 5.10 Update 14 can lead to an unauthenticated remote attacker to potentially trigger a Server Side Request Forgery attac…

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-0862

Published Mar 23, 2022

A lack of password change protection vulnerability in a depreciated API of McAfee Enterprise ePolicy Orchestrator (ePO) prior to 5.10 Update 13 allows a remote attacker to change…

CVSS 3.1 · Low
Vendor/product tagsBeta · best-effort

CVE-2022-0861

Published Mar 23, 2022

A XML Extended entity vulnerability in McAfee Enterprise ePolicy Orchestrator (ePO) prior to 5.10 Update 13 allows a remote administrator attacker to upload a malicious XML file t…

CVSS 3.5 · Low
Vendor/product tagsBeta · best-effort

CVE-2022-0859

Published Mar 23, 2022

McAfee Enterprise ePolicy Orchestrator (ePO) prior to 5.10 Update 13 allows a local attacker to point an ePO server to an arbitrary SQL server during the restoration of the ePO se…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-0858

Published Mar 23, 2022

A cross-site scripting (XSS) vulnerability in McAfee Enterprise ePolicy Orchestrator (ePO) prior to 5.10 Update 13 allows a remote attacker to potentially obtain access to an ePO…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-0857

Published Mar 23, 2022

A reflected cross-site scripting (XSS) vulnerability in McAfee Enterprise ePolicy Orchestrator (ePO) prior to 5.10 Update 13 allows a remote attacker to potentially obtain access…

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-0842

Published Mar 23, 2022

A blind SQL injection vulnerability in McAfee Enterprise ePolicy Orchestrator (ePO) prior to 5.10 Update 13 allows a remote authenticated attacker to potentially obtain informatio…

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-31835

Published Oct 22, 2021

Cross-Site Scripting vulnerability in McAfee ePolicy Orchestrator (ePO) prior to 5.10 Update 11 allows ePO administrators to inject arbitrary web script or HTML via a specific par…

CVSS 4.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-31834

Published Oct 22, 2021

Stored Cross-Site Scripting vulnerability in McAfee ePolicy Orchestrator (ePO) prior to 5.10 Update 11 allows ePO administrators to inject arbitrary web script or HTML via multipl…

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-2432

Published Jul 21, 2021

Vulnerability in the Java SE product of Oracle Java SE (component: JNDI). The supported version that is affected is Java SE: 7u301. Difficult to exploit vulnerability allows unaut…

CVSS 3.7 · Low
Vendor/product tagsBeta · best-effort

CVE-2021-2161

Published Apr 22, 2021

Vulnerability in the Java SE, Java SE Embedded, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: Libraries). Supported versions that are affected are Java S…

CVSS 5.9 · Medium

CVE-2021-23890

Published Mar 26, 2021

Information leak vulnerability in the Agent Handler of McAfee ePolicy Orchestrator (ePO) prior to 5.10 Update 10 allows an unauthenticated user to download McAfee product packages…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-23889

Published Mar 26, 2021

Cross-Site Scripting vulnerability in McAfee ePolicy Orchestrator (ePO) prior to 5.10 Update 10 allows ePO administrators to inject arbitrary web script or HTML via multiple param…

CVSS 3.5 · Low
Vendor/product tagsBeta · best-effort

CVE-2021-23888

Published Mar 26, 2021

Unvalidated client-side URL redirect vulnerability in McAfee ePolicy Orchestrator (ePO) prior to 5.10 Update 10 could cause an authenticated ePO user to load an untrusted site in…

CVSS 6.3 · Medium
Vendor/product tagsBeta · best-effort
Showing 1-25 of 84 CVEsPage 1 of 4