Vulnerability Details CVE-2016-8027
SQL injection vulnerability in core services in Intel Security McAfee ePolicy Orchestrator (ePO) 5.3.2 and earlier and 5.1.3 and earlier allows attackers to alter a SQL query, which can result in disclosure of information within the database or impersonation of an agent without authentication via a specially crafted HTTP post.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.162
EPSS Ranking 94.4%
CVSS Severity
CVSS v3 Score 10.0
CVSS v2 Score 7.5
Products affected by CVE-2016-8027
-
cpe:2.3:a:mcafee:epolicy_orchestrator:5.1.0
-
cpe:2.3:a:mcafee:epolicy_orchestrator:5.1.1
-
cpe:2.3:a:mcafee:epolicy_orchestrator:5.1.2
-
cpe:2.3:a:mcafee:epolicy_orchestrator:5.1.3
-
cpe:2.3:a:mcafee:epolicy_orchestrator:5.3.0
-
cpe:2.3:a:mcafee:epolicy_orchestrator:5.3.1
-
cpe:2.3:a:mcafee:epolicy_orchestrator:5.3.2