Show plain JSON{"containers": {"cna": {"affected": [{"product": "n/a", "vendor": "n/a", "versions": [{"status": "affected", "version": "n/a"}]}], "datePublic": "2015-01-06T00:00:00", "descriptions": [{"lang": "en", "value": "McAfee ePolicy Orchestrator (ePO) before 4.6.9 and 5.x before 5.1.2 uses the same secret key across different customers' installations, which allows attackers to obtain the administrator password by leveraging knowledge of the encrypted password."}], "problemTypes": [{"descriptions": [{"description": "n/a", "lang": "en", "type": "text"}]}], "providerMetadata": {"dateUpdated": "2017-09-07T15:57:01", "orgId": "8254265b-2729-46b6-b9e3-3dfca2d5bfca", "shortName": "mitre"}, "references": [{"name": "72298", "tags": ["vdb-entry", "x_refsource_BID"], "url": "http://www.securityfocus.com/bid/72298"}, {"name": "20150112 Re: McAfee ePolicy Orchestrator Authenticated XXE and Credential Exposure", "tags": ["mailing-list", "x_refsource_FULLDISC"], "url": "http://seclists.org/fulldisclosure/2015/Jan/37"}, {"tags": ["x_refsource_CONFIRM"], "url": "https://kc.mcafee.com/corporate/index?page=content&id=SB10095"}, {"tags": ["x_refsource_MISC"], "url": "http://packetstormsecurity.com/files/129827/McAfee-ePolicy-Orchestrator-Authenticated-XXE-Credential-Exposure.html"}, {"name": "20150106 McAfee ePolicy Orchestrator Authenticated XXE and Credential Exposure", "tags": ["mailing-list", "x_refsource_FULLDISC"], "url": "http://seclists.org/fulldisclosure/2015/Jan/8"}, {"name": "macafee-cve20150922-info-disc(99949)", "tags": ["vdb-entry", "x_refsource_XF"], "url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/99949"}, {"name": "1031519", "tags": ["vdb-entry", "x_refsource_SECTRACK"], "url": "http://www.securitytracker.com/id/1031519"}, {"tags": ["x_refsource_MISC"], "url": "https://gist.github.com/brandonprry/692e553975bf29aeaf2c"}], "x_legacyV4Record": {"CVE_data_meta": {"ASSIGNER": "cve@mitre.org", "ID": "CVE-2015-0922", "STATE": "PUBLIC"}, "affects": {"vendor": {"vendor_data": [{"product": {"product_data": [{"product_name": "n/a", "version": {"version_data": [{"version_value": "n/a"}]}}]}, "vendor_name": "n/a"}]}}, "data_format": "MITRE", "data_type": "CVE", "data_version": "4.0", "description": {"description_data": [{"lang": "eng", "value": "McAfee ePolicy Orchestrator (ePO) before 4.6.9 and 5.x before 5.1.2 uses the same secret key across different customers' installations, which allows attackers to obtain the administrator password by leveraging knowledge of the encrypted password."}]}, "problemtype": {"problemtype_data": [{"description": [{"lang": "eng", "value": "n/a"}]}]}, "references": {"reference_data": [{"name": "72298", "refsource": "BID", "url": "http://www.securityfocus.com/bid/72298"}, {"name": "20150112 Re: McAfee ePolicy Orchestrator Authenticated XXE and Credential Exposure", "refsource": "FULLDISC", "url": "http://seclists.org/fulldisclosure/2015/Jan/37"}, {"name": "https://kc.mcafee.com/corporate/index?page=content&id=SB10095", "refsource": "CONFIRM", "url": "https://kc.mcafee.com/corporate/index?page=content&id=SB10095"}, {"name": "http://packetstormsecurity.com/files/129827/McAfee-ePolicy-Orchestrator-Authenticated-XXE-Credential-Exposure.html", "refsource": "MISC", "url": "http://packetstormsecurity.com/files/129827/McAfee-ePolicy-Orchestrator-Authenticated-XXE-Credential-Exposure.html"}, {"name": "20150106 McAfee ePolicy Orchestrator Authenticated XXE and Credential Exposure", "refsource": "FULLDISC", "url": "http://seclists.org/fulldisclosure/2015/Jan/8"}, {"name": "macafee-cve20150922-info-disc(99949)", "refsource": "XF", "url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/99949"}, {"name": "1031519", "refsource": "SECTRACK", "url": "http://www.securitytracker.com/id/1031519"}, {"name": "https://gist.github.com/brandonprry/692e553975bf29aeaf2c", "refsource": "MISC", "url": "https://gist.github.com/brandonprry/692e553975bf29aeaf2c"}]}}}, "adp": [{"providerMetadata": {"orgId": "af854a3a-2127-422b-91ae-364da2661108", "shortName": "CVE", "dateUpdated": "2024-08-06T04:26:11.339Z"}, "title": "CVE Program Container", "references": [{"name": "72298", "tags": ["vdb-entry", "x_refsource_BID", "x_transferred"], "url": "http://www.securityfocus.com/bid/72298"}, {"name": "20150112 Re: McAfee ePolicy Orchestrator Authenticated XXE and Credential Exposure", "tags": ["mailing-list", "x_refsource_FULLDISC", "x_transferred"], "url": "http://seclists.org/fulldisclosure/2015/Jan/37"}, {"tags": ["x_refsource_CONFIRM", "x_transferred"], "url": "https://kc.mcafee.com/corporate/index?page=content&id=SB10095"}, {"tags": ["x_refsource_MISC", "x_transferred"], "url": "http://packetstormsecurity.com/files/129827/McAfee-ePolicy-Orchestrator-Authenticated-XXE-Credential-Exposure.html"}, {"name": "20150106 McAfee ePolicy Orchestrator Authenticated XXE and Credential Exposure", "tags": ["mailing-list", "x_refsource_FULLDISC", "x_transferred"], "url": "http://seclists.org/fulldisclosure/2015/Jan/8"}, {"name": "macafee-cve20150922-info-disc(99949)", "tags": ["vdb-entry", "x_refsource_XF", "x_transferred"], "url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/99949"}, {"name": "1031519", "tags": ["vdb-entry", "x_refsource_SECTRACK", "x_transferred"], "url": "http://www.securitytracker.com/id/1031519"}, {"tags": ["x_refsource_MISC", "x_transferred"], "url": "https://gist.github.com/brandonprry/692e553975bf29aeaf2c"}]}]}, "cveMetadata": {"assignerOrgId": "8254265b-2729-46b6-b9e3-3dfca2d5bfca", "assignerShortName": "mitre", "cveId": "CVE-2015-0922", "datePublished": "2015-01-09T18:00:00", "dateReserved": "2015-01-09T00:00:00", "dateUpdated": "2024-08-06T04:26:11.339Z", "state": "PUBLISHED"}, "dataType": "CVE_RECORD", "dataVersion": "5.1"}