CVE-2014-3485

The REST API in the ovirt-engine in oVirt, as used in Red Hat Enterprise Virtualization (rhevm) 3.4, allows remote authenticated users to read arbitrary files and have other unspecified impact via unknown vectors, related to an XML External Entity (XXE) issue.
Configurations

Configuration 1 (hide)

cpe:2.3:a:redhat:enterprise_virtualization:3.4:*:*:*:*:*:*:*

History

21 Nov 2024, 02:08

Type Values Removed Values Added
References () http://rhn.redhat.com/errata/RHSA-2014-0814.html - Vendor Advisory () http://rhn.redhat.com/errata/RHSA-2014-0814.html - Vendor Advisory
References () http://www.securitytracker.com/id/1030501 - () http://www.securitytracker.com/id/1030501 -

Information

Published : 2014-07-11 14:55

Updated : 2024-11-21 02:08


NVD link : CVE-2014-3485

Mitre link : CVE-2014-3485

CVE.ORG link : CVE-2014-3485


JSON object : View

Products Affected

redhat

  • enterprise_virtualization
CWE
CWE-200

Exposure of Sensitive Information to an Unauthorized Actor