QID 730816

Date Published: 2023-09-28

QID 730816: Skyhigh (McAfee) Web Gateway Security Update for expat

libexpat before 2.4.9 has a use-after-free in the doContent function in xmlparse.c Affected Versions:
9.x prior to 9.2.27
10.x prior to 10.2.16
11.x prior to 11.2.5
12.x prior to 12.0.1

QID Detection Logic :
This QID retrieves Skyhigh Web Gateway version and checks to see if it's vulnerable.

Successful exploitation of this vulnerability could lead to a security breach or could affect integrity, availability, and confidentiality.

  • CVSS V3 rated as Critical - 8.1 severity.
  • CVSS V2 rated as Medium - 5.4 severity.
  • Solution
    Customers are advised to update to updated versions 11.2.5 and 10.2.16 and 9.2.27

    CVEs related to QID 730816

    Software Advisories
    Advisory ID Software Component Link
    Skyhigh Web Gateway 11.x URL Logo success.myshn.net/Release_Notes/Latest_Secure_Web_Gateway_(On-prem)_Releases/Secure_Web_Gateway_11.2.x_Release_Notes