CVE-2012-4583: McAfee Email And Web Security
Medium severity, CVSS 4.0. EPSS: 0.9% chance of exploitation in the next 30 days.
McAfee Email and Web Security (EWS) 5.x before 5.5 Patch 6 and 5.6 before Patch 3, and McAfee Email Gateway (MEG) 7.0 before Patch 1, allows remote authenticated users to obtain the session tokens of arbitrary users by navigating within the Dashboard.
Affected products
- McAfee Email And Web Security: version 5.0 only; version 5.5 only; version 5.6 only
- McAfee Email Gateway: version 7.0 only
Published 2012-08-22. Last modified 2026-06-16.