CVE-2017-4015

C

lickjacking vulnerability in the server in McAfee Network Data Loss Prevention (NDLP) 9.3.x allows remote authenticated users to inject arbitrary web script or HTML via HTTP response header.

References
Link Resource
http://www.securitytracker.com/id/1038523 Broken Link Third Party Advisory VDB Entry
https://kc.mcafee.com/corporate/index?page=content&id=SB10198 Broken Link Vendor Advisory
http://www.securitytracker.com/id/1038523 Broken Link Third Party Advisory VDB Entry
https://kc.mcafee.com/corporate/index?page=content&id=SB10198 Broken Link Vendor Advisory
Configurations

Configuration 1 (hide)

cpe:2.3:a:mcafee:network_data_loss_prevention:*:*:*:*:*:*:*:*

History

21 Nov 2024, 03:26

Type Values Removed Values Added
References () http://www.securitytracker.com/id/1038523 - Broken Link, Third Party Advisory, VDB Entry () http://www.securitytracker.com/id/1038523 - Broken Link, Third Party Advisory, VDB Entry
References () https://kc.mcafee.com/corporate/index?page=content&id=SB10198 - Broken Link, Vendor Advisory () https://kc.mcafee.com/corporate/index?page=content&id=SB10198 - Broken Link, Vendor Advisory

Information

Published : 2017-05-17 21:29

Updated : 2025-04-20 01:37


NVD link : CVE-2017-4015

Mitre link : CVE-2017-4015

CVE.ORG link : CVE-2017-4015


JSON object : View

CWE
CWE-1021

Improper Restriction of Rendered UI Layers or Frames