Intrusion Prevention

McAfee.ePolicy.Orchestrator.XML.Entity.Injection

Description

This indicates an attack attempt against an XML External Entity (XXE) vulnerability in McAfee ePolicy Orchestrator.
The vulnerability is due to an improper validation of users supplied data while the affected application handles a crafted XML file. A remote attacker can exploit this to gain unauthorized access to sensitive information via a crafted XML file.

Affected Products

McAfee ePolicy Orchestrator prior to 4.6.9
McAfee ePolicy Orchestrator prior to 5.1.2

Impact

Information Disclosure: Remote attackers can gain sensitive information from vulnerable systems.

CVE References

CVE-2015-0921