Critical severity10.0NVD Advisory· Published Mar 14, 2017· Updated Jun 17, 2026
CVE-2016-8027
CVE-2016-8027
Description
SQL injection vulnerability in core services in Intel Security McAfee ePolicy Orchestrator (ePO) 5.3.2 and earlier and 5.1.3 and earlier allows attackers to alter a SQL query, which can result in disclosure of information within the database or impersonation of an agent without authentication via a specially crafted HTTP post.
Affected products
3cpe:2.3:a:mcafee:epolicy_orchestrator:*:*:*:*:*:*:*:*+ 1 more
- cpe:2.3:a:mcafee:epolicy_orchestrator:*:*:*:*:*:*:*:*range: >=5.1.0,<=5.1.3
- (no CPE)range: <=5.3.2, <=5.1.3
- Range: <=5.3.2, <=5.1.3
Patches
Vulnerability mechanics
References
3- www.securityfocus.com/bid/95981nvdThird Party AdvisoryVDB Entry
- www.securitytracker.com/id/1037777nvdThird Party AdvisoryVDB Entry
- kc.mcafee.com/corporate/indexnvdVendor Advisory
News mentions
0No linked articles in our index yet.