VulnerabilityModified
CVE-2017-3899
SQL injection vulnerability in Intel Security Advanced Threat Defense (ATD) Linux 3.6.0 and earlier allows remote authenticated users to obtain product information via a crafted HTTP request parameter.
MEDIUM 6.5EPSS 1.70%
Does this matter?
Lower severity and a low EPSS score (1.70%). Track it; it rarely justifies an emergency change on its own.
Description
SQL injection vulnerability in Intel Security Advanced Threat Defense (ATD) Linux 3.6.0 and earlier allows remote authenticated users to obtain product information via a crafted HTTP request parameter.
- CVSS 3.0
- 6.5 MEDIUMCVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
- EPSS
- 1.70% probability · 76th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-89
- Affected
- mcafee/advanced threat defense
- Source
- secure@intel.com
References
- http://www.securityfocus.com/bid/96929Third Party Advisory, Vendor Advisory
- https://kc.mcafee.com/corporate/index?page=content&id=SB10189Vendor Advisory
- http://www.securityfocus.com/bid/96929Third Party Advisory, Vendor Advisory
- https://kc.mcafee.com/corporate/index?page=content&id=SB10189Vendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.