#VU13451 Improper access control in McAfee ePolicy Orchestrator - CVE-2018-6671
Published: June 25, 2018 / Updated: June 17, 2021
McAfee ePolicy Orchestrator
McAfee
Description
The vulnerability allows a remote authenticated attacker to obtain potentially sensitive information.
The vulnerability exists due to improper access control. A remote attacker can send a specially crafted HTTP request to bypass localhost-only access controls for some functions and obtain arbitrary data.