CVE Vulnerabilities

CVE-2012-4594

Published: Aug 22, 2012 | Modified: Apr 11, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
4 MEDIUM
AV:N/AC:L/Au:S/C:P/I:N/A:N
RedHat/V2
RedHat/V3
Ubuntu
root.io logo minimus.io logo echo.ai logo

McAfee ePolicy Orchestrator (ePO) 4.6.1 and earlier allows remote authenticated users to bypass intended access restrictions, and obtain sensitive information from arbitrary reporting panels, via a modified ID value in a console URL.

Affected Software

NameVendorStart VersionEnd Version
Epolicy_orchestratorMcafee**
Epolicy_orchestratorMcafee*4.6.1 (including)
Epolicy_orchestratorMcafee2.0 (including)2.0 (including)
Epolicy_orchestratorMcafee2.5 (including)2.5 (including)
Epolicy_orchestratorMcafee2.5-sp1 (including)2.5-sp1 (including)
Epolicy_orchestratorMcafee2.5.1 (including)2.5.1 (including)
Epolicy_orchestratorMcafee3.0 (including)3.0 (including)
Epolicy_orchestratorMcafee3.0-sp2a (including)3.0-sp2a (including)
Epolicy_orchestratorMcafee3.5.0 (including)3.5.0 (including)
Epolicy_orchestratorMcafee3.6.0 (including)3.6.0 (including)
Epolicy_orchestratorMcafee3.6.1 (including)3.6.1 (including)
Epolicy_orchestratorMcafee4.0 (including)4.0 (including)
Epolicy_orchestratorMcafee4.5.0 (including)4.5.0 (including)
Epolicy_orchestratorMcafee4.6.0 (including)4.6.0 (including)

References