CVE-2016-8027
critical
CVSS v3
10.0
CVSS v2
7.5
VIR risk
10.0
Description
SQL injection vulnerability in core services in Intel Security McAfee ePolicy Orchestrator (ePO) 5.3.2 and earlier and 5.1.3 and earlier allows attackers to alter a SQL query, which can result in disclosure of information within the database or impersonation of an agent without authentication via a specially crafted HTTP post.
Predictions
Exploit likelihood
98%
Patch ETA
—
Heuristic predictions, AS-IS, for prioritization only.
Mitigations
Vendor advisory: secure@intel.com — https://kc.mcafee.com/corporate/index?page=content&id=SB10187
Application impact
| Vendor | Product | Versions | Fixed |
|---|---|---|---|
| mcafee | epolicy_orchestrator | {"startIncluding":"5.1.0","endIncluding":"5.1.3"} | |
References
CWEs
CWE-89
Verify integrity in audit chain (admin only). AS-IS.