McAfee Agent Remote Log Viewing Directory Traversal Vulnerability Fixed by 5.0.2


Description   A directory traversal vulnerability was reported in McAfee Agent.
A remote attacker could exploit it by using a specially crafted URL in order to access to unspecified information.
This vulnerability is located in the remote log viewing functionality.
     
Vulnerable Products   Vulnerable Software:
Agent (McAfee) - 5.0, 5.0.0, 5.0.1
     
Solution   Version 5.0.2 of McAfee Agent fixes this vulnerability.
     
CVE  
     
References   - SB10130 : McAfee Agent patch fixes a vulnerability in its remote log viewing functionality
https://kc.mcafee.com/corporate/index?page=content&id=SB10130
     
Vulnerability Manager Detection   No
     
IPS Protection  
ASQ Engine alarm Available Since
Misc : Directory traversal - parameter starting with ../
3.2.0
Directory traversal using ..\..
3.2.0
Directory traversal
3.2.0
Directory traversal backward root folder
3.2.0
     


 
 
 
 
 Risk level 
Low 

 Vulnerability First Public Report Date 
2015-08-31 

 Target Type 
Server 

 Possible exploit 
Remote