cbcvebase.
CVE-2022-0861
published 2022-03-23

CVE-2022-0861: A XML Extended entity vulnerability in McAfee Enterprise ePolicy Orchestrator (ePO) prior to 5.10 Update 13 allows a remote administrator attacker to upload a…

PriorityP417low3.8CVSS 3.1
AVNACLPRHUINSUCLILAN
EPSS
0.44%
35.4th percentile
A XML Extended entity vulnerability in McAfee Enterprise ePolicy Orchestrator (ePO) prior to 5.10 Update 13 allows a remote administrator attacker to upload a malicious XML file through the extension import functionality. The impact is limited to some access to confidential information and some ability to alter data.

Affected

3 ranges
VendorProductVersion rangeFixed in
mcafeeepolicy_orchestrator< 5.10.05.10.0
mcafeeepolicy_orchestrator
mcafee_llcmcafee_epolicy_orchestrator>= unspecified < 5.10 CU 135.10 CU 13

CVSS provenance

nvdv3.13.8LOWCVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:L/A:N
nvdv2.05.5MEDIUMAV:N/AC:L/Au:S/C:P/I:P/A:N
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.