CVE-2019-14258: XEE
Published Aug 21, 2019
·Updated
The XML-RPC subsystem in Zenoss 2.5.3 allows XXE attacks that lead to unauthenticated information disclosure via port 9988.
Affected Software
1 affected component
Zenoss Zenoss=2.5.3
Event History
Aug 21, 2019
CVE Published
via MITRE·06:33 PM
Data Sourced
via MITRE·06:33 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2019-14258?
CVE-2019-14258 has a medium severity level due to the potential for unauthenticated information disclosure.
2
How do I fix CVE-2019-14258?
To fix CVE-2019-14258, upgrade Zenoss to the latest version where this vulnerability has been addressed.
3
What software is affected by CVE-2019-14258?
CVE-2019-14258 affects Zenoss version 2.5.3.
4
What type of attack does CVE-2019-14258 facilitate?
CVE-2019-14258 allows for XML External Entity (XXE) attacks.
5
What can be exposed due to CVE-2019-14258?
CVE-2019-14258 can lead to unauthenticated information disclosure.