CA Cloud Service Management CVE-2014-8474 XML External Entity Injection Vulnerability
BID:70926
Info
CA Cloud Service Management CVE-2014-8474 XML External Entity Injection Vulnerability
| Bugtraq ID: | 70926 |
| Class: | Input Validation Error |
| CVE: |
CVE-2014-8474 |
| Remote: | Yes |
| Local: | No |
| Published: | Nov 03 2014 12:00AM |
| Updated: | Nov 03 2014 12:00AM |
| Credit: | Vladislav Mladenov, Julian Krautwald, Florian Feldmann and Christian Mainka |
| Vulnerable: |
Computer Associates Cloud Service Management 0 |
| Not Vulnerable: |
Computer Associates Cloud Service Management 2014 |
Discussion
CA Cloud Service Management CVE-2014-8474 XML External Entity Injection Vulnerability
CA Cloud Service Management is prone to an unspecified XML External Entity injection vulnerability.
Attackers can exploit this issue to obtain potentially sensitive information or cause a denial-of-service condition. This may lead to further attacks.
CA Cloud Service Management is prone to an unspecified XML External Entity injection vulnerability.
Attackers can exploit this issue to obtain potentially sensitive information or cause a denial-of-service condition. This may lead to further attacks.
Exploit / POC
CA Cloud Service Management CVE-2014-8474 XML External Entity Injection Vulnerability
An attacker can exploit this issue using a web browser.
An attacker can exploit this issue using a web browser.
Solution / Fix
CA Cloud Service Management CVE-2014-8474 XML External Entity Injection Vulnerability
Solution:
Updates are available. Please see the references or vendor advisory for more information.
Solution:
Updates are available. Please see the references or vendor advisory for more information.