First published: Thu May 14 2015(Updated: )
XML external entity (XXE) in the RPC interface in Spacewalk and Red Hat Network (RHN) Satellite 5.7 and earlier allows remote attackers to read arbitrary files and possibly have other unspecified impact via unknown vectors.
Credit: secalert@redhat.com
Affected Software | Affected Version | How to fix |
---|---|---|
Red Hat Satellite | <=5.7 | |
SUSE Manager Server | =1.7 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2014-8162 is considered a critical vulnerability due to the potential for remote file access and exploitation.
To fix CVE-2014-8162, upgrade to the latest version of Red Hat Satellite or SUSE Manager that patches this vulnerability.
CVE-2014-8162 affects Red Hat Satellite versions up to 5.7 and SUSE Manager version 1.7.
The potential impacts of CVE-2014-8162 include unauthorized access to sensitive files and potential overall system compromise.
Yes, CVE-2014-8162 can be exploited remotely by attackers using XML external entities.