PT-2015-4022 · Red Hat · Spacewalk+1
Published
2015-05-14
·
Updated
2023-02-13
·
CVE-2014-8162
CVSS v2.0
7.5
High
| Vector | AV:N/AC:L/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
Red Hat Network Satellite versions 5.7 and earlier
Spacewalk versions 5.7 and earlier
Description
The issue is related to an XML external entity (XXE) in the RPC interface. This allows remote attackers to read arbitrary files and possibly have other unspecified impact.
Recommendations
For Red Hat Network Satellite versions 5.7 and earlier, update to a version later than 5.7.
For Spacewalk versions 5.7 and earlier, update to a version later than 5.7.
As a temporary workaround, consider restricting access to the RPC interface until a patch is available.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Red Hat Network Satellite
Spacewalk