CVE-2017-3907: McAfee Threat Intelligence Exchange
Critical severity, CVSS 9.8. EPSS: 1.6% chance of exploitation in the next 30 days.
Code Injection vulnerability in the ePolicy Orchestrator (ePO) extension in McAfee Threat Intelligence Exchange (TIE) Server 2.1.0 and earlier allows remote attackers to execute arbitrary HTML code to be reflected in the response web page via unspecified vector.
Affected products
- McAfee McAfee Threat Intelligence Exchange: version 2.1.0 only
Published 2018-06-13. Last modified 2026-06-17.