CVE-2017-3902
Summary
| CVE | CVE-2017-3902 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2017-02-13 16:59:00 UTC |
| Updated | 2017-07-26 01:29:00 UTC |
| Description | Cross-site scripting (XSS) vulnerability in the Web user interface (UI) in Intel Security ePO 5.1.3, 5.1.2, 5.1.1, and 5.1.0 allows authenticated users to inject malicious Java scripts via bypassing input validation. |
Risk And Classification
Problem Types: CWE-79
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Mcafee | Epolicy Orchestrator | 5.1.0 | All | All | All |
| Application | Mcafee | Epolicy Orchestrator | 5.1.1 | All | All | All |
| Application | Mcafee | Epolicy Orchestrator | 5.1.2 | All | All | All |
| Application | Mcafee | Epolicy Orchestrator | 5.1.3 | All | All | All |
| Application | Mcafee | Epolicy Orchestrator | 5.1.0 | All | All | All |
| Application | Mcafee | Epolicy Orchestrator | 5.1.1 | All | All | All |
| Application | Mcafee | Epolicy Orchestrator | 5.1.2 | All | All | All |
| Application | Mcafee | Epolicy Orchestrator | 5.1.3 | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| McAfee ePolicy Orchestrator CVE-2017-3902 Cross Site Scripting Vulnerability | BID | www.securityfocus.com | |
| McAfee ePolicy Orchestrator Input Validation Flaw Lets Remote Users Conduct Cross-Site Scripting Attacks - SecurityTracker | SECTRACK | www.securitytracker.com | |
| Article Not Available; Try Logging In | CONFIRM | kc.mcafee.com | Patch, Vendor Advisory |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.