CVE-2016-8027: McAfee Epolicy Orchestrator
Critical severity, CVSS 10.0. EPSS: 5.7% chance of exploitation in the next 30 days.
SQL injection vulnerability in core services in Intel Security McAfee ePolicy Orchestrator (ePO) 5.3.2 and earlier and 5.1.3 and earlier allows attackers to alter a SQL query, which can result in disclosure of information within the database or impersonation of an agent without authentication via a specially crafted HTTP post.
Affected products
- McAfee Epolicy Orchestrator: from 5.1.0, up to and including 5.1.3; from 5.3.0, up to and including 5.3.2
Published 2017-03-14. Last modified 2026-06-17.