7.5
CVSSv2

CVE-2014-8162

Published: 14/05/2015 Updated: 13/02/2023
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
VMScore: 668
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

XML external entity (XXE) in the RPC interface in Spacewalk and Red Hat Network (RHN) Satellite 5.7 and previous versions allows remote malicious users to read arbitrary files and possibly have other unspecified impact via unknown vectors.

Vulnerable Product Search on Vulmon Subscribe to Product

redhat network satellite

suse manager 1.7

Vendor Advisories

It was found that the RPC interface in Satellite would resolve external entities, allowing an attacker to conduct XML External Entity (XXE) attacks A remote attacker could use this flaw to read files accessible to the user running the Satellite server, and potentially perform other more advanced XXE attacks ...