CVE-2012-4594: McAfee Epolicy Orchestrator

Medium severity, CVSS 4.0. EPSS: 1% chance of exploitation in the next 30 days.

McAfee ePolicy Orchestrator (ePO) 4.6.1 and earlier allows remote authenticated users to bypass intended access restrictions, and obtain sensitive information from arbitrary reporting panels, via a modified ID value in a console URL.

Affected products

  • McAfee Epolicy Orchestrator: any version; up to and including 4.6.1; version 2.0 only; version 2.5 only; version 2.5.1 only; version 3.0 only; …

Published 2012-08-22. Last modified 2026-06-16.