CVE-2017-3907
published 2018-06-13CVE-2017-3907: Code Injection vulnerability in the ePolicy Orchestrator (ePO) extension in McAfee Threat Intelligence Exchange (TIE) Server 2.1.0 and earlier allows remote…
PriorityP351critical9.8CVSS 3.0
AVNACLPRNUINSUCHIHAH
EPSS
1.58%
72.9th percentile
Code Injection vulnerability in the ePolicy Orchestrator (ePO) extension in McAfee Threat Intelligence Exchange (TIE) Server 2.1.0 and earlier allows remote attackers to execute arbitrary HTML code to be reflected in the response web page via unspecified vector.
Affected
3 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apache | nifi | — | — |
| mcafee | mcafee_threat_intelligence_exchange | — | — |
| mcafee | threat_intelligence_exchange_server | >= 2.1.0 < 2.1.0 Hotfix 1 | 2.1.0 Hotfix 1 |
CVSS provenance
nvdv3.09.8CRITICALCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvdv2.07.5HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
vendor_apache7.5
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-xjmv-7wr2-r7c4: Code Injection vulnerability in the ePolicy Orchestrator (ePO) extension in McAfee Threat Intelligence Exchange (TIE) Server 2
ghsa_unreviewed·2022-05-13
CVE-2017-3907 [CRITICAL] CWE-94 GHSA-xjmv-7wr2-r7c4: Code Injection vulnerability in the ePolicy Orchestrator (ePO) extension in McAfee Threat Intelligence Exchange (TIE) Server 2
Code Injection vulnerability in the ePolicy Orchestrator (ePO) extension in McAfee Threat Intelligence Exchange (TIE) Server 2.1.0 and earlier allows remote attackers to execute arbitrary HTML code to be reflected in the response web page via unspecified vector.
Apache
Apache nifi: CVE-2017-7667
vendor_apache·CVSS 7.5
CVE-2017-7667 Apache nifi: CVE-2017-7667
Apache nifi: CVE-2017-7667
Title: Potential Cross-Frame Scripting from Improper Frame Access Restrictions Published: 2017-05-08 Severity: Medium Products: Apache NiFi Affected Versions: 0.0.1 to 0.7.3 and 1.0.0 to 1.2.0 Fixed Versions: 0.7.4 and 1.3.0 Reporter: Matt Gilman References CVE Record: CVE-2017-7667 NVD Record: CVE-2017-7667 Apache Jira Issue: NIFI-3907 Apache NiFi needs to establish the response header telling browsers to only allow framing with the same origin. NiFi 0.7.4 and 1.3.0 set the response header. Users running a prior release should upgrade to 0.7.4 or 1.3.0.
Severity: moderate
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2018-06-13
Published