McAfee ePolicy Orchestrator (ePO) 4.6.1 and earlier allows remote authenticated users to bypass intended access restrictions, and obtain sensitive information from arbitrary reporting panels, via a modified ID value in a console URL.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Epolicy_orchestrator | Mcafee | * | * |
Epolicy_orchestrator | Mcafee | * | 4.6.1 (including) |
Epolicy_orchestrator | Mcafee | 2.0 (including) | 2.0 (including) |
Epolicy_orchestrator | Mcafee | 2.5 (including) | 2.5 (including) |
Epolicy_orchestrator | Mcafee | 2.5-sp1 (including) | 2.5-sp1 (including) |
Epolicy_orchestrator | Mcafee | 2.5.1 (including) | 2.5.1 (including) |
Epolicy_orchestrator | Mcafee | 3.0 (including) | 3.0 (including) |
Epolicy_orchestrator | Mcafee | 3.0-sp2a (including) | 3.0-sp2a (including) |
Epolicy_orchestrator | Mcafee | 3.5.0 (including) | 3.5.0 (including) |
Epolicy_orchestrator | Mcafee | 3.6.0 (including) | 3.6.0 (including) |
Epolicy_orchestrator | Mcafee | 3.6.1 (including) | 3.6.1 (including) |
Epolicy_orchestrator | Mcafee | 4.0 (including) | 4.0 (including) |
Epolicy_orchestrator | Mcafee | 4.5.0 (including) | 4.5.0 (including) |
Epolicy_orchestrator | Mcafee | 4.6.0 (including) | 4.6.0 (including) |