CVE-2014-8162

critical

Description

XML external entity (XXE) in the RPC interface in Spacewalk and Red Hat Network (RHN) Satellite 5.7 and earlier allows remote attackers to read arbitrary files and possibly have other unspecified impact via unknown vectors.

References

http://www.securityfocus.com/bid/74595

http://rhn.redhat.com/errata/RHSA-2015-0957.html

http://lists.opensuse.org/opensuse-security-announce/2015-05/msg00020.html

Details

Source: Mitre, NVD

Published: 2015-05-14

Updated: 2023-02-13

Risk Information

CVSS v2

Base Score: 7.5

Vector: CVSS2#AV:N/AC:L/Au:N/C:P/I:P/A:P

Severity: High

CVSS v3

Base Score: 9.1

Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N

Severity: Critical