CVE-2014-8162

Red Hat Network Satellite < 5.7 - XML External Entity Injection

Title source: llm
STIX 2.1

Description

XML external entity (XXE) in the RPC interface in Spacewalk and Red Hat Network (RHN) Satellite 5.7 and earlier allows remote attackers to read arbitrary files and possibly have other unspecified impact via unknown vectors.

References (3)

Core 3
Core References
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/74595
Vendor Advisory vendor-advisory x_refsource_redhat
http://rhn.redhat.com/errata/RHSA-2015-0957.html

Scores

EPSS 0.0061
EPSS Percentile 69.9%

Details

Status published
Products (2)
redhat/network_satellite < 5.7
suse/manager 1.7
Published May 14, 2015
Tracked Since Feb 18, 2026