VYPR
High severity8.1NVD Advisory· Published Nov 14, 2019· Updated Jun 17, 2026

CVE-2019-3661

CVE-2019-3661

Description

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') in McAfee Advanced Threat Defense (ATD) prior to 4.8 allows remote authenticated attacker to execute database commands via carefully constructed time based payloads.

Affected products

3
  • cpe:2.3:a:mcafee:advanced_threat_defense:*:*:*:*:*:*:*:*+ 2 more
    • cpe:2.3:a:mcafee:advanced_threat_defense:*:*:*:*:*:*:*:*range: <4.8
    • (no CPE)range: <4.8
    • (no CPE)range: unspecified

Patches

Vulnerability mechanics

References

1

News mentions

0

No linked articles in our index yet.