VendorsMcAfeeepolicy_orchestrator5.1.1
Vulnerabilities

McAfee ePolicy Orchestrator 5.1.1

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

5CVEs
CVE-2017-3936
McAfee ePolicy Orchestrator (ePO) - OS Command Injection vulnerability
Published 2018-06-13 · Modified
9.8EPSS 0.014
CVE-2015-2859
Intel McAfee ePolicy Orchestrator (ePO) 4.x through 4.6.9 and 5.x through 5.1.2 does not validate server names and Certification Authority names in X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.
Published 2015-06-23 · Modified
5.8EPSS 0.010
CVE-2017-3902
Cross-site scripting (XSS) vulnerability in the Web user interface (UI) in Intel Security ePO 5.1.3, 5.1.2, 5.1.1, and 5.1.0 allows authenticated users to inject malicious Java scripts via bypassing input validation.
Published 2017-02-13 · Modified
5.4EPSS 0.007
CVE-2015-0922
McAfee ePolicy Orchestrator (ePO) before 4.6.9 and 5.x before 5.1.2 uses the same secret key across different customers' installations, which allows attackers to obtain the administrator password by leveraging knowledge of the encrypted password.
Published 2015-01-09 · Modified
5.0EPSS 0.133
CVE-2015-0921
XML external entity (XXE) vulnerability in the Server Task Log in McAfee ePolicy Orchestrator (ePO) before 4.6.9 and 5.x before 5.1.2 allows remote authenticated users to read arbitrary files via the conditionXML parameter to the taskLogTable to orionUpdateTableFilter.do.
Published 2015-01-09 · Modified
4.0EPSS 0.174