Vulnerabilities > Mcafee

DATE CVE VULNERABILITY TITLE RISK
2022-04-14 CVE-2022-1257 Insecure Storage of Sensitive Information vulnerability in Mcafee Agent
Insecure storage of sensitive information vulnerability in MA for Linux, macOS, and Windows prior to 5.7.6 allows a local user to gain access to sensitive information through storage in ma.db.
local
low complexity
mcafee CWE-922
5.5
2022-04-14 CVE-2022-1258 SQL Injection vulnerability in Mcafee Agent
A blind SQL injection vulnerability in the ePolicy Orchestrator (ePO) extension of MA prior to 5.7.6 can be exploited by an authenticated administrator on ePO to perform arbitrary SQL queries in the back-end database, potentially leading to command execution on the server.
network
low complexity
mcafee CWE-89
7.2
2022-03-23 CVE-2022-0857 Cross-site Scripting vulnerability in Mcafee Epolicy Orchestrator
A reflected cross-site scripting (XSS) vulnerability in McAfee Enterprise ePolicy Orchestrator (ePO) prior to 5.10 Update 13 allows a remote attacker to potentially obtain access to an ePO administrator's session by convincing the attacker to click on a carefully crafted link.
network
low complexity
mcafee CWE-79
6.1
2022-03-23 CVE-2022-0858 Cross-site Scripting vulnerability in Mcafee Epolicy Orchestrator
A cross-site scripting (XSS) vulnerability in McAfee Enterprise ePolicy Orchestrator (ePO) prior to 5.10 Update 13 allows a remote attacker to potentially obtain access to an ePO administrator's session by convincing the attacker to click on a carefully crafted link.
network
low complexity
mcafee CWE-79
4.7
2022-03-23 CVE-2022-0859 Insufficiently Protected Credentials vulnerability in Mcafee Epolicy Orchestrator
McAfee Enterprise ePolicy Orchestrator (ePO) prior to 5.10 Update 13 allows a local attacker to point an ePO server to an arbitrary SQL server during the restoration of the ePO server.
local
low complexity
mcafee CWE-522
6.7
2022-03-23 CVE-2022-0861 XXE vulnerability in Mcafee Epolicy Orchestrator
A XML Extended entity vulnerability in McAfee Enterprise ePolicy Orchestrator (ePO) prior to 5.10 Update 13 allows a remote administrator attacker to upload a malicious XML file through the extension import functionality.
network
low complexity
mcafee CWE-611
3.8
2022-03-23 CVE-2022-0862 Improper Authentication vulnerability in Mcafee Epolicy Orchestrator
A lack of password change protection vulnerability in a depreciated API of McAfee Enterprise ePolicy Orchestrator (ePO) prior to 5.10 Update 13 allows a remote attacker to change the password of a compromised session without knowing the existing user's password.
network
low complexity
mcafee CWE-287
5.3
2022-03-23 CVE-2022-0842 SQL Injection vulnerability in Mcafee Epolicy Orchestrator
A blind SQL injection vulnerability in McAfee Enterprise ePolicy Orchestrator (ePO) prior to 5.10 Update 13 allows a remote authenticated attacker to potentially obtain information from the ePO database.
network
low complexity
mcafee CWE-89
4.9
2022-03-10 CVE-2022-0815 Exposure of Resource to Wrong Sphere vulnerability in Mcafee Webadvisor 4.1.1.48
Improper access control vulnerability in McAfee WebAdvisor Chrome and Edge browser extensions up to 8.1.0.1895 allows a remote attacker to gain access to McAfee WebAdvisor settings and other details about the user’s system.
network
low complexity
mcafee CWE-668
7.3
2022-01-24 CVE-2021-4088 SQL Injection vulnerability in Mcafee Data Loss Prevention 11.6.401
SQL injection vulnerability in Data Loss Protection (DLP) ePO extension 11.8.x prior to 11.8.100, 11.7.x prior to 11.7.101, and 11.6.401 allows a remote authenticated attacker to inject unfiltered SQL into the DLP part of the ePO database.
network
low complexity
mcafee CWE-89
7.2