CVE-2014-2205
6.3
Vector
AV:N/AC:M/Au:S/C:C/I:N/A:N
Exploitability: 6.8 / Impact: 6.9
Source: NVD
Description
The Import and Export Framework in McAfee ePolicy Orchestrator (ePO) before 4.6.7 Hotfix 940148 allows remote authenticated users with permissions to add dashboards to read arbitrary files by importing a crafted XML file, related to an XML External Entity (XXE) issue.
Affected (8)
Products: Mcafee: Epolicy Orchestrator
Configuration A
| Vulnerable Software | Affected Versions |
|---|---|
| Up to 4.6.7 |
Related CWEs
References (10)
Source: cve@mitre.org
Source: cve@mitre.org
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Exploit
Timeline
No history available yet.