Unrated severityNVD Advisory· Published Mar 24, 2014· Updated Jun 17, 2026
CVE-2014-2587
CVE-2014-2587
Description
SQL injection vulnerability in jsp/reports/ReportsAudit.jsp in McAfee Asset Manager 6.6 allows remote authenticated users to execute arbitrary SQL commands via the username of an audit report (aka user parameter).
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
2cpe:2.3:a:mcafee:asset_manager:6.6:*:*:*:*:*:*:*+ 1 more
- cpe:2.3:a:mcafee:asset_manager:6.6:*:*:*:*:*:*:*
- (no CPE)range: 6.6
Patches
Vulnerability mechanics
References
7- packetstormsecurity.com/files/125775/McAfee-Cloud-SSO-Asset-Manager-Issues.htmlnvdExploit
- seclists.org/fulldisclosure/2014/Mar/325nvdExploit
- www.exploit-db.com/exploits/32368nvdExploit
- www.osvdb.org/104634nvd
- www.securityfocus.com/bid/66302nvd
- www.securitytracker.com/id/1029927nvd
- exchange.xforce.ibmcloud.com/vulnerabilities/91929nvd
News mentions
0No linked articles in our index yet.