About.aspx in the Portal in McAfee Enterprise Mobility Manager (EMM) before 10.0 discloses the name of the user account for an IIS worker process, which allows remote attackers to obtain potentially sensitive information by visiting this page.
The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.
Link | Tags |
---|---|
https://kc.mcafee.com/corporate/index?page=content&id=SB10022 | vendor advisory |
https://exchange.xforce.ibmcloud.com/vulnerabilities/78221 | vdb entry |