

Rewterz Threat Advisory – Multiple Microsoft .NET Core, Visual Studio, Dynamics 365
October 25, 2021
Rewterz Threat Advisory – CVE-2021-22965 – Pulse Connect Secure
October 25, 2021
Rewterz Threat Advisory – Multiple Microsoft .NET Core, Visual Studio, Dynamics 365
October 25, 2021
Rewterz Threat Advisory – CVE-2021-22965 – Pulse Connect Secure
October 25, 2021Severity
Low
Analysis Summary
CVE-2021-31835: CVE-2021-31834
McAfee ePolicy Orchestrator is vulnerable to cross-site scripting, caused by improper validation of user-supplied input. A remote authenticated attacker could exploit this vulnerability to inject malicious script into a Web page which would be executed in a victim’s Web browser within the security context of the hosting Web site, once the page is viewed. An attacker could use this vulnerability to steal the victim’s cookie-based authentication credentials.
Impact
- Cross-Site Scripting
Affected Vendors
McAfee
Affected Products
- McAfee ePolicy Orchestrator 2.5.1
- McAfee ePolicy Orchestrator 2.0
- McAfee ePolicy Orchestrator 2.5
- McAfee ePolicy Orchestrator 3.0
- McAfee ePolicy Orchestrator 3.5.0 SP3
- McAfee ePolicy Orchestrator 3.0 SP2
- McAfee ePolicy Orchestrator 3.6.1
- McAfee ePolicy Orchestrator 4.0
- McAfee ePolicy Orchestrator 2.5 SP1
- McAfee ePolicy Orchestrator 3.5.0
- McAfee ePolicy Orchestrator 3.6.0
- McAfee ePolicy Orchestrator 3.5.0 SP6
- McAfee ePolicy Orchestrator 1.0
- McAfee ePolicy Orchestrator 1.1
- McAfee ePolicy Orchestrator 3.0 SP2a
- McAfee ePolicy Orchestrator 3.5.5
- McAfee Epolicy Orchestrator 4.5.0
- McAfee Epolicy Orchestrator 4.6.0
- McAfee Epolicy Orchestrator 4.6.1
- McAfee ePolicy Orchestrator 4.6.6
- McAfee ePolicy Orchestrator 4.6.7
- McAfee ePolicy Orchestrator 4.6.8
- McAfee ePolicy Orchestrator 5.1.1
- McAfee ePolicy Orchestrator 5.1.2
- McAfee ePolicy Orchestrator 4.6.9
- McAfee ePolicy Orchestrator 5.1.3
- McAfee ePolicy Orchestrator 5.3.0
- McAfee ePolicy Orchestrator 5.9.0
- McAfee ePolicy Orchestrator 5.3.2
- McAfee ePolicy Orchestrator 5.3.1
- McAfee ePolicy Orchestrator 5.3.3
- McAfee ePolicy Orchestrator 5.9.1
- McAfee ePolicy Orchestrator 5.1.0
- McAfee ePolicy Orchestrator 5.10.0
Remediation
Refer to McAfee Security Bulletin ID: SB10366 for patch, upgrade or suggested workaround information.