CVE-2014-2588: McAfee Asset Manager

Medium severity, CVSS 4.0. EPSS: 7.3% chance of exploitation in the next 30 days.

Directory traversal vulnerability in servlet/downloadReport in McAfee Asset Manager 6.6 allows remote authenticated users to read arbitrary files via a .. (dot dot) in the reportFileName parameter.

Affected products

  • McAfee Asset Manager: version 6.6 only

Published 2014-03-24. Last modified 2026-06-17.