VulnerabilityModified
CVE-2017-4015
Clickjacking vulnerability in the server in McAfee Network Data Loss Prevention (NDLP) 9.3.x allows remote authenticated users to inject arbitrary web script or HTML via HTTP response header.
MEDIUM 4.5EPSS 1.20%
Does this matter?
Lower severity and a low EPSS score (1.20%). Track it; it rarely justifies an emergency change on its own.
Description
Clickjacking vulnerability in the server in McAfee Network Data Loss Prevention (NDLP) 9.3.x allows remote authenticated users to inject arbitrary web script or HTML via HTTP response header.
- CVSS 3.1
- 4.5 MEDIUMCVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:N/I:H/A:N
- EPSS
- 1.20% probability · 66th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-1021
- Affected
- mcafee/network data loss prevention
- Source
- secure@intel.com
References
- http://www.securitytracker.com/id/1038523Broken Link, Third Party Advisory, VDB Entry
- https://kc.mcafee.com/corporate/index?page=content&id=SB10198Broken Link, Vendor Advisory
- http://www.securitytracker.com/id/1038523Broken Link, Third Party Advisory, VDB Entry
- https://kc.mcafee.com/corporate/index?page=content&id=SB10198Broken Link, Vendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.