A blind SQL injection vulnerability in the ePolicy Orchestrator (ePO) extension of MA prior to 5.7.6 can be exploited by an authenticated administrator on ePO to perform arbitrary SQL queries in the back-end database, potentially leading to command execution on the server.
References
Link | Resource |
---|---|
https://kc.mcafee.com/corporate/index?page=content&id=SB10382 | Broken Link |
History
No history.
MITRE Information
Status: PUBLISHED
Assigner: trellix
Published: 2022-04-14T13:50:12
Updated: 2022-04-14T13:50:12
Reserved: 2022-04-06T00:00:00
Link: CVE-2022-1258
JSON object: View
NVD Information
Status : Analyzed
Published: 2022-04-14T15:15:08.067
Modified: 2023-11-15T19:30:13.107
Link: CVE-2022-1258
JSON object: View
Redhat Information
No data.
CWE