McAfee Email and Web Security (EWS) 5.x before 5.5 Patch 6 and 5.6 before Patch 3, and McAfee Email Gateway (MEG) 7.0 before Patch 1, allows remote authenticated users to obtain the session tokens of arbitrary users by navigating within the Dashboard.
The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.
Link | Tags |
---|---|
http://archives.neohapsis.com/archives/bugtraq/2012-03/0161.html | mailing list |
https://kc.mcafee.com/corporate/index?page=content&id=SB10020 | vendor advisory |