CVE-2017-4014 — Session Fixation in Network Data Loss Prevention
Severity
8.0HIGHNVD
EPSS
0.4%
top 39.25%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedMay 17
Latest updateMay 17
Description
Session Side jacking vulnerability in the server in McAfee Network Data Loss Prevention (NDLP) 9.3.x allows remote authenticated users to view, add, and remove users via modification of the HTTP request.
CVSS vector
CVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:HExploitability: 2.1 | Impact: 5.9
Affected Packages2 packages
🔴Vulnerability Details
1GHSA▶
GHSA-c4fc-2334-8h36: Session Side jacking vulnerability in the server in McAfee Network Data Loss Prevention (NDLP) 9↗2022-05-17