The Import and Export Framework in McAfee ePolicy Orchestrator (ePO) before 4.6.7 Hotfix 940148 allows remote authenticated users with permissions to add dashboards to read arbitrary files by importing a crafted XML file, related to an XML External Entity (XXE) issue.
References
Configurations
Configuration 1 (hide)
|
Information
Published : 2014-02-26 07:55
Updated : 2018-10-09 12:43
NVD link : CVE-2014-2205
Mitre link : CVE-2014-2205
JSON object : View
CWE
CWE-264
Permissions, Privileges, and Access Controls
Products Affected
mcafee
- epolicy_orchestrator