McAfee ePolicy Orchestrator Information Disclosure Vulnerability
BID:7114
Info
McAfee ePolicy Orchestrator Information Disclosure Vulnerability
| Bugtraq ID: | 7114 |
| Class: | Design Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Mar 17 2003 12:00AM |
| Updated: | Mar 17 2003 12:00AM |
| Credit: | The discovery of this vulnerability has been credited to @stake. |
| Vulnerable: |
McAfee ePolicy Orchestrator 2.5.1 |
| Not Vulnerable: | |
Discussion
McAfee ePolicy Orchestrator Information Disclosure Vulnerability
It has been discovered that the McAfee ePolicy Ochestrator Agent fails to carry out any authentication. As a result, anonymous remote users may be capable of obtaining sensitive log data stored by the agent. The exploitation of this vulnerability could allow an attacker to obtain sensitive information that could aid in launching further attacks.
It has been discovered that the McAfee ePolicy Ochestrator Agent fails to carry out any authentication. As a result, anonymous remote users may be capable of obtaining sensitive log data stored by the agent. The exploitation of this vulnerability could allow an attacker to obtain sensitive information that could aid in launching further attacks.
Exploit / POC
McAfee ePolicy Orchestrator Information Disclosure Vulnerability
No exploit is required.
No exploit is required.
Solution / Fix
McAfee ePolicy Orchestrator Information Disclosure Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
References
McAfee ePolicy Orchestrator Information Disclosure Vulnerability
References:
References: