CVE-2014-8162

Severity
7.5HIGH
EPSS
0.6%
top 30.38%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedMay 14
Latest updateMay 17

Description

XML external entity (XXE) in the RPC interface in Spacewalk and Red Hat Network (RHN) Satellite 5.7 and earlier allows remote attackers to read arbitrary files and possibly have other unspecified impact via unknown vectors.

CVSS vector

AV:N/AC:L/C:P/I:P/A:PExploitability: 10.0 | Impact: 6.4

Affected Packages2 packages

🔴Vulnerability Details

2
GHSA
GHSA-r4x8-hgr8-2fhj: XML external entity (XXE) in the RPC interface in Spacewalk and Red Hat Network (RHN) Satellite 52022-05-17
CVEList
CVE-2014-8162: XML external entity (XXE) in the RPC interface in Spacewalk and Red Hat Network (RHN) Satellite 52015-05-14

📋Vendor Advisories

1
Red Hat
Satellite5: RPC API XML External Entities file disclosure2015-05-11

💬Community

1
Bugzilla
CVE-2014-8162 Satellite5: RPC API XML External Entities file disclosure2015-01-29