Vulnerability Description
Intel McAfee ePolicy Orchestrator (ePO) 4.6.9 and earlier, 5.0.x, 5.1.x before 5.1.3 Hotfix 1106041, and 5.3.x before 5.3.1 Hotfix 1106041 allow remote attackers to execute arbitrary code via a crafted serialized Java object, related to the Apache Commons Collections (ACC) library.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Mcafee | Epolicy Orchestrator | <= 4.6.9 |
References
- https://kc.mcafee.com/corporate/index?page=content&id=SB10144Vendor Advisory
- https://www.kb.cert.org/vuls/id/576313Third Party AdvisoryUS Government Resource
- https://kc.mcafee.com/corporate/index?page=content&id=SB10144Vendor Advisory
- https://www.kb.cert.org/vuls/id/576313Third Party AdvisoryUS Government Resource
FAQ
What is CVE-2015-8765?
CVE-2015-8765 is a vulnerability with a CVSS score of 8.3 (HIGH). Intel McAfee ePolicy Orchestrator (ePO) 4.6.9 and earlier, 5.0.x, 5.1.x before 5.1.3 Hotfix 1106041, and 5.3.x before 5.3.1 Hotfix 1106041 allow remote attackers to execute arbitrary code via a crafte...
How severe is CVE-2015-8765?
CVE-2015-8765 has been rated HIGH with a CVSS base score of 8.3/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2015-8765?
Check the references section above for vendor advisories and patch information. Affected products include: Mcafee Epolicy Orchestrator.