CVE-2017-3902: McAfee Epolicy Orchestrator
Medium severity, CVSS 5.4. EPSS: 0.7% chance of exploitation in the next 30 days.
Cross-site scripting (XSS) vulnerability in the Web user interface (UI) in Intel Security ePO 5.1.3, 5.1.2, 5.1.1, and 5.1.0 allows authenticated users to inject malicious Java scripts via bypassing input validation.
Affected products
- McAfee Epolicy Orchestrator: version 5.1.0 only; version 5.1.1 only; version 5.1.2 only; version 5.1.3 only
Published 2017-02-13. Last modified 2026-06-17.