Rewterz
Rewterz Threat Advisory – Multiple Microsoft .NET Core, Visual Studio, Dynamics 365
October 25, 2021
Rewterz
Rewterz Threat Advisory – CVE-2021-22965 – Pulse Connect Secure
October 25, 2021

Rewterz Threat Advisory – Multiple McAfee ePolicy Orchestrator Vulnerabilities

Severity

Low

Analysis Summary

CVE-2021-31835: CVE-2021-31834

McAfee ePolicy Orchestrator is vulnerable to cross-site scripting, caused by improper validation of user-supplied input. A remote authenticated attacker could exploit this vulnerability to inject malicious script into a Web page which would be executed in a victim’s Web browser within the security context of the hosting Web site, once the page is viewed. An attacker could use this vulnerability to steal the victim’s cookie-based authentication credentials.

Impact

  • Cross-Site Scripting

Affected Vendors

McAfee

Affected Products

  • McAfee ePolicy Orchestrator 2.5.1
  • McAfee ePolicy Orchestrator 2.0
  • McAfee ePolicy Orchestrator 2.5
  • McAfee ePolicy Orchestrator 3.0
  • McAfee ePolicy Orchestrator 3.5.0 SP3
  • McAfee ePolicy Orchestrator 3.0 SP2
  • McAfee ePolicy Orchestrator 3.6.1
  • McAfee ePolicy Orchestrator 4.0
  • McAfee ePolicy Orchestrator 2.5 SP1
  • McAfee ePolicy Orchestrator 3.5.0
  • McAfee ePolicy Orchestrator 3.6.0
  • McAfee ePolicy Orchestrator 3.5.0 SP6
  • McAfee ePolicy Orchestrator 1.0
  • McAfee ePolicy Orchestrator 1.1
  • McAfee ePolicy Orchestrator 3.0 SP2a
  • McAfee ePolicy Orchestrator 3.5.5
  • McAfee Epolicy Orchestrator 4.5.0
  • McAfee Epolicy Orchestrator 4.6.0
  • McAfee Epolicy Orchestrator 4.6.1
  • McAfee ePolicy Orchestrator 4.6.6
  • McAfee ePolicy Orchestrator 4.6.7
  • McAfee ePolicy Orchestrator 4.6.8
  • McAfee ePolicy Orchestrator 5.1.1
  • McAfee ePolicy Orchestrator 5.1.2
  • McAfee ePolicy Orchestrator 4.6.9
  • McAfee ePolicy Orchestrator 5.1.3
  • McAfee ePolicy Orchestrator 5.3.0
  • McAfee ePolicy Orchestrator 5.9.0
  • McAfee ePolicy Orchestrator 5.3.2
  • McAfee ePolicy Orchestrator 5.3.1
  • McAfee ePolicy Orchestrator 5.3.3
  • McAfee ePolicy Orchestrator 5.9.1
  • McAfee ePolicy Orchestrator 5.1.0
  • McAfee ePolicy Orchestrator 5.10.0

Remediation

Refer to McAfee Security Bulletin ID: SB10366 for patch, upgrade or suggested workaround information.

https://kc.mcafee.com/corporate/index?page=content&id=SB10366