Vulnerability   
Search   
    Search 324607 CVE descriptions
and 145615 test descriptions,
access 10,000+ cross references.
Tests   CVE   All  

CVE ID:CVE-2015-0921
Description:XML external entity (XXE) vulnerability in the Server Task Log in McAfee ePolicy Orchestrator (ePO) before 4.6.9 and 5.x before 5.1.2 allows remote authenticated users to read arbitrary files via the conditionXML parameter to the taskLogTable to orionUpdateTableFilter.do.
Test IDs: None available
Cross References: Common Vulnerability Exposure (CVE) ID: CVE-2015-0921
http://seclists.org/fulldisclosure/2015/Jan/8
http://seclists.org/fulldisclosure/2015/Jan/37
http://packetstormsecurity.com/files/129827/McAfee-ePolicy-Orchestrator-Authenticated-XXE-Credential-Exposure.html
https://gist.github.com/brandonprry/692e553975bf29aeaf2c
http://www.securitytracker.com/id/1031519
http://secunia.com/advisories/61922
XForce ISS Database: macafee-cve20150921-info-disc(99950)
https://exchange.xforce.ibmcloud.com/vulnerabilities/99950




© 1998-2025 E-Soft Inc. All rights reserved.