MEDIUM · 4.4

CVE-2019-3612

Information Disclosure vulnerability in McAfee DXL Platform and TIE Server in DXL prior to 5.0.1 HF2 and TIE prior to 2.3.1 HF1 allows Authenticated users to view sensitive information in plain text v...

Vulnerability Description

Information Disclosure vulnerability in McAfee DXL Platform and TIE Server in DXL prior to 5.0.1 HF2 and TIE prior to 2.3.1 HF1 allows Authenticated users to view sensitive information in plain text via the GUI or command line.

CVSS Score

4.4

MEDIUM

CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N
Attack Vector
LOCAL
Attack Complexity
LOW
Privileges Required
HIGH
User Interaction
NONE
Scope
UNCHANGED
Confidentiality
HIGH
Integrity
NONE
Availability
NONE

Affected Products

VendorProductVersions
McafeeData Exchange Layer>= 4.0.0, <= 4.1.2
McafeeThreat Intelligence Exchange>= 2.0.0, <= 2.3.1

Related Weaknesses (CWE)

References

FAQ

What is CVE-2019-3612?

CVE-2019-3612 is a vulnerability with a CVSS score of 4.4 (MEDIUM). Information Disclosure vulnerability in McAfee DXL Platform and TIE Server in DXL prior to 5.0.1 HF2 and TIE prior to 2.3.1 HF1 allows Authenticated users to view sensitive information in plain text v...

How severe is CVE-2019-3612?

CVE-2019-3612 has been rated MEDIUM with a CVSS base score of 4.4/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2019-3612?

Check the references section above for vendor advisories and patch information. Affected products include: Mcafee Data Exchange Layer, Mcafee Threat Intelligence Exchange.