CVE-2019-3630: McAfee Enterprise Security Manager
High severity, CVSS 7.2. EPSS: 2% chance of exploitation in the next 30 days.
Command Injection vulnerability in McAfee Enterprise Security Manager (ESM) prior to 11.2.0 and prior to 10.4.0 allows authenticated user to execute arbitrary code via specially crafted parameters.
Affected products
- McAfee Enterprise Security Manager: before 10.4.0 (fixed in 10.4.0); from 11.0.0, before 11.2.0 (fixed in 11.2.0)
Published 2019-06-27. Last modified 2026-06-17.