High
McAfee Data Loss Prevention (DLP) ePO extension is vulnerable to SQL injection. A remote authenticated attacker could send specially-crafted SQL statements to ePO database using the DLP part, which could allow the attacker to execute arbitrary code on the ePO server with privilege escalation.
McAfee
Refer to McAfee Security Advisory for patch, upgrade or suggested workaround information.