McAfee.ePolicy.Orchestrator.XML.Entity.Injection

description-logoDescription

This indicates an attack attempt against an XML External Entity (XXE) vulnerability in McAfee ePolicy Orchestrator.
The vulnerability is due to an improper validation of users supplied data while the affected application handles a crafted XML file. A remote attacker can exploit this to gain unauthorized access to sensitive information via a crafted XML file.

affected-products-logoAffected Products

McAfee ePolicy Orchestrator prior to 4.6.9
McAfee ePolicy Orchestrator prior to 5.1.2

Impact logoImpact

Information Disclosure: Remote attackers can gain sensitive information from vulnerable systems.

Telemetry logoTelemetry

Coverage

IPS (Regular DB)
IPS (Extended DB)