CVE-2018-6672Sensitive Information Exposure in Epolicy Orchestrator

Severity
6.5MEDIUMNVD
CNA5.7
EPSS
0.5%
top 32.21%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedJun 15
Latest updateMay 13

Description

Information disclosure vulnerability in McAfee ePolicy Orchestrator (ePO) 5.3.0 through 5.3.3 and 5.9.0 through 5.9.1 allows authenticated users to view sensitive information in plain text format via unspecified vectors.

CVSS vector

CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:NExploitability: 2.8 | Impact: 3.6

Affected Packages2 packages

CVEListV5mcafee/epolicy_orchestrator5.3.0 through 5.3.35.3.3 with hotfix EPO5xHF1229850+1
NVDmcafee/epolicy_orchestrator5.3.05.3.3+1

🔴Vulnerability Details

2
GHSA
GHSA-4q27-f9mh-jgq2: Information disclosure vulnerability in McAfee ePolicy Orchestrator (ePO) 52022-05-13
CVEList
SB10240 - ePolicy Orchestrator (ePO) - Information disclosure vulnerablity2018-06-15
CVE-2018-6672 — Sensitive Information Exposure | cvebase