CVE-2021-4088
Blind SQL injection in DLP ePO extension
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
SQL injection vulnerability in Data Loss Protection (DLP) ePO extension 11.8.x prior to 11.8.100, 11.7.x prior to 11.7.101, and 11.6.401 allows a remote authenticated attacker to inject unfiltered SQL into the DLP part of the ePO database. This could lead to remote code execution on the ePO server with privilege escalation.
Una vulnerabilidad de inyección SQL en la extensión de ePO de Data Loss Protection (DLP) versiones 11.8.x anteriores a 11.8.100, versiones 11.7.x anteriores a 11.7.101 y versiones 11.6.401, permite a un atacante remoto autenticado inyectar SQL sin filtrar en la parte de DLP de la base de datos de ePO. Esto podría conllevar a una ejecución de código remota en el servidor de ePO con escalada de privilegios
CVSS Scores
SSVC
- Decision:-
Timeline
- 2021-12-09 CVE Reserved
- 2022-01-24 CVE Published
- 2023-11-16 EPSS Updated
- 2024-08-03 CVE Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-89: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
CAPEC
References (1)
URL | Tag | Source |
---|---|---|
https://kc.mcafee.com/corporate/index?page=content&id=SB10376 | Broken Link |
URL | Date | SRC |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Mcafee Search vendor "Mcafee" | Data Loss Prevention Search vendor "Mcafee" for product "Data Loss Prevention" | >= 11.7.0 < 11.7.101 Search vendor "Mcafee" for product "Data Loss Prevention" and version " >= 11.7.0 < 11.7.101" | epolicy_orchestrator |
Affected
| ||||||
Mcafee Search vendor "Mcafee" | Data Loss Prevention Search vendor "Mcafee" for product "Data Loss Prevention" | >= 11.8.0 < 11.8.100 Search vendor "Mcafee" for product "Data Loss Prevention" and version " >= 11.8.0 < 11.8.100" | epolicy_orchestrator |
Affected
| ||||||
Mcafee Search vendor "Mcafee" | Data Loss Prevention Search vendor "Mcafee" for product "Data Loss Prevention" | 11.6.401 Search vendor "Mcafee" for product "Data Loss Prevention" and version "11.6.401" | epolicy_orchestrator |
Affected
|