CVE-2012-4599: McAfee Smartfilter Administration

High severity, CVSS 10.0. EPSS: 3.9% chance of exploitation in the next 30 days.

McAfee SmartFilter Administration, and SmartFilter Administration Bess Edition, before 4.2.1.01 does not require authentication for access to the JBoss Remote Method Invocation (RMI) interface, which allows remote attackers to execute arbitrary code via a crafted .war file.

Affected products

  • McAfee Smartfilter Administration: up to and including 4.2.1

Published 2012-08-22. Last modified 2026-06-16.