Vulnerability Description
A blind SQL injection vulnerability in McAfee Enterprise ePolicy Orchestrator (ePO) prior to 5.10 Update 13 allows a remote authenticated attacker to potentially obtain information from the ePO database. The data obtained is dependent on the privileges the attacker has and to obtain sensitive data the attacker would require administrator privileges.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Mcafee | Epolicy Orchestrator | < 5.10.0 |
Related Weaknesses (CWE)
References
- https://kc.mcafee.com/corporate/index?page=content&id=SB10379Broken Link
- https://kc.mcafee.com/corporate/index?page=content&id=SB10379Broken Link
FAQ
What is CVE-2022-0842?
CVE-2022-0842 is a vulnerability with a CVSS score of 5.4 (MEDIUM). A blind SQL injection vulnerability in McAfee Enterprise ePolicy Orchestrator (ePO) prior to 5.10 Update 13 allows a remote authenticated attacker to potentially obtain information from the ePO databa...
How severe is CVE-2022-0842?
CVE-2022-0842 has been rated MEDIUM with a CVSS base score of 5.4/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2022-0842?
Check the references section above for vendor advisories and patch information. Affected products include: Mcafee Epolicy Orchestrator.