CVE-2014-8162
published 2015-05-14CVE-2014-8162: XML external entity (XXE) in the RPC interface in Spacewalk and Red Hat Network (RHN) Satellite 5.7 and earlier allows remote attackers to read arbitrary files…
PriorityP344high7.5CVSS 2.0
AVNACLAuNCPIPAP
EPSS
2.69%
84.2th percentile
XML external entity (XXE) in the RPC interface in Spacewalk and Red Hat Network (RHN) Satellite 5.7 and earlier allows remote attackers to read arbitrary files and possibly have other unspecified impact via unknown vectors.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| redhat | network_satellite | <= 5.7 | — |
| suse | manager | — | — |
CVSS provenance
nvdv2.07.5HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
vendor_redhat7.5HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
Satellite5: RPC API XML External Entities file disclosure
vendor_redhat·2015-05-11·CVSS 7.5
CVE-2014-8162 [HIGH] CWE-611 Satellite5: RPC API XML External Entities file disclosure
Satellite5: RPC API XML External Entities file disclosure
XML external entity (XXE) in the RPC interface in Spacewalk and Red Hat Network (RHN) Satellite 5.7 and earlier allows remote attackers to read arbitrary files and possibly have other unspecified impact via unknown vectors.
It was found that the RPC interface in Satellite would resolve external entities, allowing an attacker to conduct XML External Entity (XXE) attacks. A remote attacker could use this flaw to read files accessible to the user running the Satellite server, and potentially perform other more advanced XXE attacks.
GHSA
GHSA-r4x8-hgr8-2fhj: XML external entity (XXE) in the RPC interface in Spacewalk and Red Hat Network (RHN) Satellite 5
ghsa_unreviewed·2022-05-17
CVE-2014-8162 [HIGH] GHSA-r4x8-hgr8-2fhj: XML external entity (XXE) in the RPC interface in Spacewalk and Red Hat Network (RHN) Satellite 5
XML external entity (XXE) in the RPC interface in Spacewalk and Red Hat Network (RHN) Satellite 5.7 and earlier allows remote attackers to read arbitrary files and possibly have other unspecified impact via unknown vectors.
No detection rules found.
No public exploits indexed.
http://lists.opensuse.org/opensuse-security-announce/2015-05/msg00020.htmlhttp://rhn.redhat.com/errata/RHSA-2015-0957.htmlhttp://www.securityfocus.com/bid/74595http://lists.opensuse.org/opensuse-security-announce/2015-05/msg00020.htmlhttp://rhn.redhat.com/errata/RHSA-2015-0957.htmlhttp://www.securityfocus.com/bid/74595
2015-05-14
Published