peter bassill · operator
$ cve CVE-2016-8027 JSON

CVE-2016-8027

10.0
CRITICAL · CVSS 3.0 · EPSS 5.7% (pctl 93)

In your normal cycle

Critical by CVSS (10), but no sign of active exploitation.

Description

SQL injection vulnerability in core services in Intel Security McAfee ePolicy Orchestrator (ePO) 5.3.2 and earlier and 5.1.3 and earlier allows attackers to alter a SQL query, which can result in disclosure of information within the database or impersonation of an agent without authentication via a specially crafted HTTP post.

Scoring

CVSS10.0 (CRITICAL, v3.0)
VectorCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
EPSS5.75% — more likely to be exploited than 93% of all CVEs
WeaknessCWE-89
On CISA KEVno
Public exploitnone known
Published2017-03-14
Last modified2026-06-17

Affected (1)

VendorProduct
mcafeeepolicy orchestrator

References

→ the Explorer  ·  watch your stack  ·  NVD