Inappropriate Encoding for output context vulnerability in McAfee Web Gateway (MWG) prior to 9.2.1 allows a remote attacker to cause MWG to return an ambiguous redirect response via getting a user to click on a malicious URL.
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:NMcafee Web Gateway
APPMcafee7.8.0 – 7.8.2.22 (excl.)8.2.0 – 8.2.9 (excl.)9.0.0 – 9.2.1 (excl.)
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
Related vulnerabilities
CVE-2021-23885CRITICAL9.0PL ✓same product
Privilege escalation w McAfee Web Gateway przez interfejs użytkownika
CVE-2020-7293CRITICAL9.0PL ✓same product
Privilege Escalation w McAfee Web Gateway — zmiana hasła root przez nieuprawnionego użytkownika
CVE-2019-9169CRITICAL9.8PL ✓same product
Heap buffer over-read w glibc przez dopasowanie regex bez uwzględnienia wielkości liter
CVE-2018-18311CRITICAL9.8PL ✓same product
Buffer overflow w Perl przez spreparowane wyrażenie regularne
CVE-2016-4448CRITICAL9.8PL ✓same product
Format string vulnerability w libxml2 umożliwiająca nieokre ślony wpływ na system