Total vulnerabilities in the database
An External XML entity (XXE) vulnerability in ePO prior to 5.10 Update 14 can lead to an unauthenticated remote attacker to potentially trigger a Server Side Request Forgery attack. This can be exploited by mimicking the Agent Handler call to ePO and passing the carefully constructed XML file through the API.
Software | From | Fixed in |
---|---|---|
mcafee / epolicy_orchestrator | 5.10.0-update_1 | 5.10.0-update_1.x |
mcafee / epolicy_orchestrator | 5.10.0-update_2 | 5.10.0-update_2.x |
mcafee / epolicy_orchestrator | 5.10.0-update_3 | 5.10.0-update_3.x |
mcafee / epolicy_orchestrator | 5.10.0-update_4 | 5.10.0-update_4.x |
mcafee / epolicy_orchestrator | 5.10.0-update_5 | 5.10.0-update_5.x |
mcafee / epolicy_orchestrator | 5.10.0-update_6 | 5.10.0-update_6.x |
mcafee / epolicy_orchestrator | 5.10.0 | 5.10.0.x |
mcafee / epolicy_orchestrator | - | 5.10.0 |
mcafee / epolicy_orchestrator | 5.10.0-update_7 | 5.10.0-update_7.x |
mcafee / epolicy_orchestrator | 5.10.0-update_8 | 5.10.0-update_8.x |
mcafee / epolicy_orchestrator | 5.10.0-update_9 | 5.10.0-update_9.x |
mcafee / epolicy_orchestrator | 5.10.0-update_10 | 5.10.0-update_10.x |
mcafee / epolicy_orchestrator | 5.10.0-update_11 | 5.10.0-update_11.x |
mcafee / epolicy_orchestrator | 5.10.0-update_12 | 5.10.0-update_12.x |
mcafee / epolicy_orchestrator | 5.10.0-update_13 | 5.10.0-update_13.x |