CVE Database
/

CVE-2019-3615

Back to search

CVE-2019-3615

Published: Mar 12, 2019

Modified: Aug 4, 2024

PUBLISHED

CVSS v3.0

5.3

MEDIUM

Description

Data Leakage Attacks vulnerability in the web interface in McAfee Database Security prior to the 4.6.6 March 2019 update allows local users to expose passwords via incorrectly auto completing password fields in the admin browser login screen.

VendorProductVersions

McAfee, LCC

McAfee Database Security (DAM)

affected
unspecified - < 4.6.6 March 2019 Update

CVSS v3.0 Details

CVSS v3.0 Vector

CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L

Attack Vector

Local

Attack Complexity

Low

Privileges Required

Low

User Interaction

None

Scope

Unchanged

Confidentiality

Low

Integrity

Low

Availability

Low

References

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now