CVE-2017-4011: McAfee Network Data Loss Prevention

Medium severity, CVSS 6.1. EPSS: 3.3% chance of exploitation in the next 30 days.

Embedding Script (XSS) in HTTP Headers vulnerability in the server in McAfee Network Data Loss Prevention (NDLP) 9.3.x allows remote attackers to get session/cookie information via modification of the HTTP request.

Affected products

  • McAfee Network Data Loss Prevention: up to and including 9.3.0

Published 2017-05-17. Last modified 2026-06-17.