CVE-2017-4011
18Vexday Risk Score
Patch soon. It has a working public exploit.
ssvc Attendepss 3.3%
exploitation probability
3.3%top 13% of all CVEs
observed exploitation
nono source reports it
Embedding Script (XSS) in HTTP Headers vulnerability in the server in McAfee Network Data Loss Prevention (NDLP) 9.3.x allows remote attackers to get session/cookie information via modification of the HTTP request.
Affected products
McAfee · Network Data Loss Prevention (NDLP)