VendorsMcAfeeepolicy_orchestratorany version
Vulnerabilities

McAfee ePolicy Orchestrator any version

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

42CVEs
CVE-2016-8027
SQL injection vulnerability in core services in Intel Security McAfee ePolicy Orchestrator (ePO) 5.3.2 and earlier and 5.1.3 and earlier allows attackers to alter a SQL query, which can result in disclosure of information within the database or impersonation of an agent without authentication via a specially crafted HTTP post.
Published 2017-03-14 · Modified
10.0EPSS 0.057
CVE-2019-3604
ePolicy Orchestrator Cloud update fixes multiple Cross-Site Request Forgery vulnerabilities
Published 2019-02-01 · Modified
8.8EPSS 0.004
CVE-2015-8765
Intel McAfee ePolicy Orchestrator (ePO) 4.6.9 and earlier, 5.0.x, 5.1.x before 5.1.3 Hotfix 1106041, and 5.3.x before 5.3.1 Hotfix 1106041 allow remote attackers to execute arbitrary code via a crafted serialized Java object, related to the Apache Commons Collections (ACC) library.
Published 2016-01-08 · Modified
8.3EPSS 0.027
CVE-2023-5444
CSRF in ePO leading to privilege escalation
Published 2023-11-17 · Modified
8.0EPSS 0.004
CVE-2013-0140
SQL injection vulnerability in the Agent-Handler component in McAfee ePolicy Orchestrator (ePO) before 4.5.7 and 4.6.x before 4.6.6 allows remote attackers to execute arbitrary SQL commands via a crafted request over the Agent-Server communication channel.
Published 2013-05-01 · Modified
7.91 PoCEPSS 0.025
CVE-2021-23840
Integer overflow in CipherUpdate
Published 2021-02-16 · Modified
7.5EPSS 0.507
CVE-2021-30639
DoS after non-blocking IO error
Published 2021-07-12 · Modified
7.5EPSS 0.069
CVE-2021-3712
Read buffer overruns processing ASN.1 strings
Published 2021-08-24 · Modified
7.4EPSS 0.504
CVE-2017-3980
A directory traversal vulnerability in the ePO Extension in McAfee ePolicy Orchestrator (ePO) 5.9.0, 5.3.2, and 5.1.3 and earlier allows remote authenticated users to execute a command of their choice via an authenticated ePO session.
Published 2017-05-18 · Modified
7.2EPSS 0.028
CVE-2022-0859
ePO database restoration vulnerability
Published 2022-03-23 · Modified
6.7EPSS 0.002
CVE-2013-4882
Multiple SQL injection vulnerabilities in McAfee ePolicy Orchestrator 4.6.6 and earlier, and the ePolicy Orchestrator (ePO) extension for McAfee Agent (MA) 4.5 and 4.6, allow remote authenticated users to execute arbitrary SQL commands via the uid parameter to (1) core/showRegisteredTypeDetails.do and (2) EPOAGENTMETA/DisplayMSAPropsDetail.do, a different vulnerability than CVE-2013-0140.
Published 2013-07-21 · Modified
6.51 PoCEPSS 0.039
CVE-2018-6671
SB10240 - ePolicy Orchestrator (ePO) - Application Protection Bypass vulnerability
Published 2018-06-15 · Modified
6.51 PoCEPSS 0.026
CVE-2018-6672
SB10240 - ePolicy Orchestrator (ePO) - Information disclosure vulnerablity
Published 2018-06-15 · Modified
6.5EPSS 0.012
CVE-2021-23890
McAfee ePO Information Leak vulnerability
Published 2021-03-26 · Modified
6.5EPSS 0.009
CVE-2014-2205
The Import and Export Framework in McAfee ePolicy Orchestrator (ePO) before 4.6.7 Hotfix 940148 allows remote authenticated users with permissions to add dashboards to read arbitrary files by importing a crafted XML file, related to an XML External Entity (XXE) issue.
Published 2014-02-26 · Modified
6.3EPSS 0.020
CVE-2021-23888
McAfee ePO unvalidated URL redirect vulnerability
Published 2021-03-26 · Modified
6.3EPSS 0.006
CVE-2022-0857
ePO Reflected Cross-site scripting vulnerability
Published 2022-03-23 · Modified
6.1EPSS 0.007
CVE-2022-3339
Reflected XSS in Trellix ePO server
Published 2022-10-18 · Modified
6.1EPSS 0.006
CVE-2023-3946
A reflected cross-site scripting (XSS) vulnerability in ePO prior to 5.10 SP1 Update 1allows a remote unauthenticated attacker to potentially obtain access to an ePO administrator's session by convincing the authenticated ePO administrator to click on a carefully crafted link. This would lead to limited access to sensitive information and limited ability to alter some information in ePO.
Published 2023-07-26 · Modified
6.1EPSS 0.006
CVE-2021-2161
Vulnerability in the Java SE, Java SE Embedded, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: Libraries). Supported versions that are affected are Java SE: 7u291, 8u281, 11.0.10, 16; Java SE Embedded: 8u281; Oracle GraalVM Enterprise Edition: 19.3.5, 20.3.1.2 and 21.0.0.2. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Java SE, Java SE Embedded, Oracle GraalVM Enterprise Edition. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Java SE, Java SE Embedded, Oracle GraalVM Enterprise Edition accessible data. Note: This vulnerability applies to Java deployments that load and run untrusted code (e.g., code that comes from the internet) and rely on the Java sandbox for security. It can also be exploited by supplying untrusted data to APIs in the specified Component. CVSS 3.1 Base Score 5.9 (Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N).
Published 2021-04-22 · Modified
5.9EPSS 0.035
CVE-2020-13938
Improper Handling of Insufficient Privileges
Published 2021-06-10 · Modified
5.5EPSS 0.119
CVE-2022-0861
ePO XML extended entity vulnerability
Published 2022-03-23 · Modified
5.5EPSS 0.005
CVE-2022-0842
ePO blind SQL Injection vulnerability
Published 2022-03-23 · Modified
5.4EPSS 0.008
CVE-2022-3338
XXE in Trellix ePO server
Published 2022-10-18 · Modified
5.4EPSS 0.005
CVE-2021-31834
McAfee ePO Cross-Site Scripting vulnerability
Published 2021-10-22 · Modified
5.4EPSS 0.005
CVE-2023-5445
An open redirect vulnerability in ePolicy Orchestrator prior to 5.10.0 CP1 Update 2, allows a remote low privileged user to modify the URL parameter for the purpose of redirecting URL request(s) to a malicious site. This impacts the dashboard area of the user interface. A user would need to be logged into ePO to trigger this vulnerability. To exploit this the attacker must change the HTTP payload post submission, prior to it reaching the ePO server.
Published 2023-11-17 · Modified
5.4EPSS 0.004
CVE-2021-33037
Incorrect Transfer-Encoding handling with HTTP/1.0
Published 2021-07-12 · Modified
5.3EPSS 0.747
CVE-2022-0862
ePO password change vulnerability
Published 2022-03-23 · Modified
5.3EPSS 0.007
CVE-2015-0922
McAfee ePolicy Orchestrator (ePO) before 4.6.9 and 5.x before 5.1.2 uses the same secret key across different customers' installations, which allows attackers to obtain the administrator password by leveraging knowledge of the encrypted password.
Published 2015-01-09 · Modified
5.0EPSS 0.133
CVE-2021-31835
McAfee ePO Cross-Site Scripting vulnerability
Published 2021-10-22 · Modified
4.8EPSS 0.006
CVE-2021-23889
McAfee ePO Cross-site Scripting vulnerability
Published 2021-03-26 · Modified
4.8EPSS 0.005
CVE-2022-0858
Cross-site scripting vulnerability in ePO
Published 2022-03-23 · Modified
4.7EPSS 0.008
CVE-2020-7318
ePolicy Orchistrator (ePO) - Cross-Site Scripting vulnerability
Published 2020-10-14 · Modified
4.6EPSS 0.010
CVE-2020-7317
ePolicy Orchistrator (ePO) - Cross-Site Scripting vulnerability
Published 2020-10-14 · Modified
4.6EPSS 0.003
CVE-2013-4883
Multiple cross-site scripting (XSS) vulnerabilities in McAfee ePolicy Orchestrator 4.6.6 and earlier, and the ePO Extension for the McAfee Agent (MA) 4.5 through 4.6, allow remote attackers to inject arbitrary web script or HTML via the (1) instanceId parameter core/loadDisplayType.do; (2) instanceId or (3) monitorUrl parameter to console/createDashboardContainer.do; uid parameter to (4) ComputerMgmt/sysDetPanelBoolPie.do or (5) ComputerMgmt/sysDetPanelSummary.do; (6) uid, (7) orion.user.security.token, or (8) ajaxMode parameter to ComputerMgmt/sysDetPanelQry.do; or (9) uid, (10) orion.user.security.token, or (11) ajaxMode parameter to ComputerMgmt/sysDetPanelSummary.do.
Published 2013-07-21 · Modified
4.31 PoCEPSS 0.051
CVE-2020-2756
Vulnerability in the Java SE, Java SE Embedded product of Oracle Java SE (component: Serialization). Supported versions that are affected are Java SE: 7u251, 8u241, 11.0.6 and 14; Java SE Embedded: 8u241. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Java SE, Java SE Embedded. Successful attacks of this vulnerability can result in unauthorized ability to cause a partial denial of service (partial DOS) of Java SE, Java SE Embedded. Note: Applies to client and server deployment of Java. This vulnerability can be exploited through sandboxed Java Web Start applications and sandboxed Java applets. It can also be exploited by supplying data to APIs in the specified Component without using sandboxed Java Web Start applications or sandboxed Java applets, such as through a web service. CVSS 3.0 Base Score 3.7 (Availability impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L).
Published 2020-04-15 · Modified
4.3EPSS 0.042
CVE-2020-2757
Vulnerability in the Java SE, Java SE Embedded product of Oracle Java SE (component: Serialization). Supported versions that are affected are Java SE: 7u251, 8u241, 11.0.6 and 14; Java SE Embedded: 8u241. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Java SE, Java SE Embedded. Successful attacks of this vulnerability can result in unauthorized ability to cause a partial denial of service (partial DOS) of Java SE, Java SE Embedded. Note: Applies to client and server deployment of Java. This vulnerability can be exploited through sandboxed Java Web Start applications and sandboxed Java applets. It can also be exploited by supplying data to APIs in the specified Component without using sandboxed Java Web Start applications or sandboxed Java applets, such as through a web service. CVSS 3.0 Base Score 3.7 (Availability impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L).
Published 2020-04-15 · Modified
4.3EPSS 0.042
CVE-2021-2432
Vulnerability in the Java SE product of Oracle Java SE (component: JNDI). The supported version that is affected is Java SE: 7u301. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Java SE. Successful attacks of this vulnerability can result in unauthorized ability to cause a partial denial of service (partial DOS) of Java SE. Note: This vulnerability applies to Java deployments, typically in clients running sandboxed Java Web Start applications or sandboxed Java applets, that load and run untrusted code (e.g., code that comes from the internet) and rely on the Java sandbox for security. This vulnerability can also be exploited by using APIs in the specified Component, e.g., through a web service which supplies data to the APIs. CVSS 3.1 Base Score 3.7 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L).
Published 2021-07-20 · Modified
4.3EPSS 0.037
CVE-2015-4559
Cross-site scripting (XSS) vulnerability in the product deployment feature in the Java core web services in Intel McAfee ePolicy Orchestrator (ePO) before 5.1.2 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
Published 2015-06-15 · Modified
4.3EPSS 0.018
CVE-2013-0141
Directory traversal vulnerability in McAfee ePolicy Orchestrator (ePO) before 4.5.7 and 4.6.x before 4.6.6 allows remote attackers to upload arbitrary files via a crafted request over the Agent-Server communication channel, as demonstrated by writing to the Software/ directory.
Published 2013-05-01 · Modified
4.3EPSS 0.011
1 / 2Next →