CVE-2017-4014 Vulnerability Details

  /     /     /  

CVE-2017-4014 Metadata Quick Info

CVE Published: 17/05/2017 | CVE Updated: 05/08/2024 | CVE Year: 2017
Source: intel | Vendor: McAfee | Product: Network Data Loss Prevention (NDLP)
Status : PUBLISHED

CVE-2017-4014 Description

Session Side jacking vulnerability in the server in McAfee Network Data Loss Prevention (NDLP) 9.3.x allows remote authenticated users to view, add, and remove users via modification of the HTTP request.

Metrics

CVSS Version: 3.1 | Base Score: n/a
Vector: n/a

l➤ Exploitability Metrics:
    Attack Vector (AV)*
    Attack Complexity (AC)*
    Privileges Required (PR)*
    User Interaction (UI)*
    Scope (S)*

l➤ Impact Metrics:
    Confidentiality Impact (C)*
    Integrity Impact (I)*
    Availability Impact (A)*

Weakness Enumeration (CWE)

CWE-ID:
CWE Name: Session Side jacking vulnerability
Source: McAfee

Common Attack Pattern Enumeration and Classification (CAPEC)

CAPEC-ID:
CAPEC Description:


Source: NVD (National Vulnerability Database).