The Import and Export Framework in McAfee ePolicy Orchestrator (ePO) before 4.6.7 Hotfix 940148 allows remote authenticated users with permissions to add dashboards to read arbitrary files by importing a crafted XML file, related to an XML External Entity (XXE) issue.
Metrics
Affected Vendors & Products
References
History
No history.
MITRE
Status: PUBLISHED
Assigner: mitre
Published: 2014-02-26T15:00:00
Updated: 2024-08-06T10:06:00.285Z
Reserved: 2014-02-26T00:00:00
Link: CVE-2014-2205
Vulnrichment
No data.
NVD
Status : Modified
Published: 2014-02-26T15:55:08.983
Modified: 2024-11-21T02:05:50.657
Link: CVE-2014-2205
Redhat
No data.