Format string vulnerability in McAfee Security ePolicy Orchestrator (ePO) 2.5.1 allows remote attackers to execute arbitrary code via an HTTP GET request with a URI containing format strings.
https://exchange.xforce.ibmcloud.com/vulnerabilities/11559
http://www.securityfocus.com/bid/7111
http://www.securityfocus.com/archive/1/315230/30/25490/threaded