McAfee ePolicy Orchestrator XML External Entity Information Disclosure Vulnerability
BID:65771
Info
McAfee ePolicy Orchestrator XML External Entity Information Disclosure Vulnerability
| Bugtraq ID: | 65771 |
| Class: | Design Error |
| CVE: |
CVE-2014-2205 |
| Remote: | Yes |
| Local: | No |
| Published: | Feb 25 2014 12:00AM |
| Updated: | Feb 27 2014 04:52PM |
| Credit: | RedTeam Pentesting |
| Vulnerable: | |
| Not Vulnerable: | |
Discussion
McAfee ePolicy Orchestrator XML External Entity Information Disclosure Vulnerability
McAfee ePolicy Orchestrator is prone to an XML External Entity vulnerability
An attacker can exploit this issue to gain access to sensitive information from the application; this may lead to further attacks.
McAfee ePolicy Orchestrator 4.6.7 and prior are vulnerable.
McAfee ePolicy Orchestrator is prone to an XML External Entity vulnerability
An attacker can exploit this issue to gain access to sensitive information from the application; this may lead to further attacks.
McAfee ePolicy Orchestrator 4.6.7 and prior are vulnerable.
Exploit / POC
McAfee ePolicy Orchestrator XML External Entity Information Disclosure Vulnerability
An attacker can exploit this issue using readily available tools.
An attacker can exploit this issue using readily available tools.
Solution / Fix
McAfee ePolicy Orchestrator XML External Entity Information Disclosure Vulnerability
Solution:
Updates are available. Please see the references or vendor advisory for more information.
Solution:
Updates are available. Please see the references or vendor advisory for more information.
References
McAfee ePolicy Orchestrator XML External Entity Information Disclosure Vulnerability
References:
References:
- ePolicy Orchestrator Product Page (McAfee)