CVE-2014-3485

The REST API in the ovirt-engine in oVirt, as used in Red Hat Enterprise Virtualization (rhevm) 3.4, allows remote authenticated users to read arbitrary files and have other unspecified impact via unknown vectors, related to an XML External Entity (XXE) issue.
Configurations

Configuration 1 (hide)

cpe:2.3:a:redhat:enterprise_virtualization:3.4:*:*:*:*:*:*:*

History

13 Feb 2023, 00:39

Type Values Removed Values Added
Summary CVE-2014-3485 ovirt-engine-api: XML eXternal Entity (XXE) flaw The REST API in the ovirt-engine in oVirt, as used in Red Hat Enterprise Virtualization (rhevm) 3.4, allows remote authenticated users to read arbitrary files and have other unspecified impact via unknown vectors, related to an XML External Entity (XXE) issue.
References
  • {'url': 'https://access.redhat.com/errata/RHSA-2014:0814', 'name': 'https://access.redhat.com/errata/RHSA-2014:0814', 'tags': [], 'refsource': 'MISC'}
  • {'url': 'https://access.redhat.com/security/cve/CVE-2014-3485', 'name': 'https://access.redhat.com/security/cve/CVE-2014-3485', 'tags': [], 'refsource': 'MISC'}
  • {'url': 'https://bugzilla.redhat.com/show_bug.cgi?id=1107472', 'name': 'https://bugzilla.redhat.com/show_bug.cgi?id=1107472', 'tags': [], 'refsource': 'MISC'}

02 Feb 2023, 16:15

Type Values Removed Values Added
Summary The REST API in the ovirt-engine in oVirt, as used in Red Hat Enterprise Virtualization (rhevm) 3.4, allows remote authenticated users to read arbitrary files and have other unspecified impact via unknown vectors, related to an XML External Entity (XXE) issue. CVE-2014-3485 ovirt-engine-api: XML eXternal Entity (XXE) flaw
References
  • (MISC) https://access.redhat.com/errata/RHSA-2014:0814 -
  • (MISC) https://access.redhat.com/security/cve/CVE-2014-3485 -
  • (MISC) https://bugzilla.redhat.com/show_bug.cgi?id=1107472 -

Information

Published : 2014-07-11 14:55

Updated : 2023-12-10 11:31


NVD link : CVE-2014-3485

Mitre link : CVE-2014-3485

CVE.ORG link : CVE-2014-3485


JSON object : View

Products Affected

redhat

  • enterprise_virtualization
CWE
CWE-200

Exposure of Sensitive Information to an Unauthorized Actor