VYPR
High severity7.2NVD Advisory· Published Jun 27, 2019· Updated Jun 17, 2026

CVE-2019-3631

CVE-2019-3631

Description

Command Injection vulnerability in McAfee Enterprise Security Manager (ESM) prior to 11.2.0 and prior to 10.4.0 allows authenticated user to execute arbitrary code via specially crafted parameters.

Affected products

3
  • cpe:2.3:a:mcafee:enterprise_security_manager:*:*:*:*:*:*:*:*+ 1 more
    • cpe:2.3:a:mcafee:enterprise_security_manager:*:*:*:*:*:*:*:*range: <10.4.0
    • (no CPE)range: <11.2.0, <10.4.0
  • McAfee, LLC/McAfee Enterprise Security Manager (ESM)v5
    Range: 11.x

Patches

Vulnerability mechanics

References

1

News mentions

0

No linked articles in our index yet.