CVE-2015-0921
Summary
| CVE | CVE-2015-0921 |
|---|---|
| State | PUBLISHED |
| Assigner | mitre |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2015-01-09 18:59:10 UTC |
| Updated | 2026-05-06 22:30:45 UTC |
| Description | XML external entity (XXE) vulnerability in the Server Task Log in McAfee ePolicy Orchestrator (ePO) before 4.6.9 and 5.x before 5.1.2 allows remote authenticated users to read arbitrary files via the conditionXML parameter to the taskLogTable to orionUpdateTableFilter.do. |
Risk And Classification
Primary CVSS: v2.0 4 from [email protected]
AV:N/AC:L/Au:S/C:P/I:N/A:N
Problem Types: NVD-CWE-Other | n/a
CVSS v2.0 Breakdown
Access Vector
NetworkAccess Complexity
LowAuthentication
SingleConfidentiality
PartialIntegrity
NoneAvailability
NoneAV:N/AC:L/Au:S/C:P/I:N/A:N
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Mcafee | Epolicy Orchestrator | 5.0.0 | All | All | All |
| Application | Mcafee | Epolicy Orchestrator | 5.0.1 | All | All | All |
| Application | Mcafee | Epolicy Orchestrator | 5.1.0 | All | All | All |
| Application | Mcafee | Epolicy Orchestrator | 5.1.1 | All | All | All |
| Application | Mcafee | Epolicy Orchestrator | All | All | All | All |
Vendor Declared Affected Products
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Security Advisory SA61922 - McAfee ePolicy Orchestrator XML External Entities Vulnerability - Secunia | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | |
| McAfee KnowledgeBase - McAfee Security Bulletin - ePO workaround prevents an XML Entity Injection and Metasploit Credential vulnerability | af854a3a-2127-422b-91ae-364da2661108 | kc.mcafee.com | Patch, Vendor Advisory |
| IBM X-Force Exchange | af854a3a-2127-422b-91ae-364da2661108 | exchange.xforce.ibmcloud.com | |
| McAfee ePolicy Orchestrator Authenticated XXE Credential Exposure ≈ Packet Storm | af854a3a-2127-422b-91ae-364da2661108 | packetstormsecurity.com | Exploit, Third Party Advisory, VDB Entry |
| McAfee ePolicy Orchestrator XML External Entity Flaw and Static Encryption Key Let Remote Authenticated Users Obtain Passwords - SecurityTracker | af854a3a-2127-422b-91ae-364da2661108 | www.securitytracker.com | |
| Full Disclosure: Re: McAfee ePolicy Orchestrator Authenticated XXE and Credential Exposure | af854a3a-2127-422b-91ae-364da2661108 | seclists.org | Mailing List, Third Party Advisory |
| Full Disclosure: McAfee ePolicy Orchestrator Authenticated XXE and Credential Exposure | af854a3a-2127-422b-91ae-364da2661108 | seclists.org | Mailing List, Third Party Advisory |
| gist:692e553975bf29aeaf2c · GitHub | af854a3a-2127-422b-91ae-364da2661108 | gist.github.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.