CVE-2014-3573

Impact:
Moderate
Public Date:
2014-09-04
CWE:
CWE-611
Bugzilla:
1125795: CVE-2014-3573 oVirt Engine: XML eXternal Entity (XXE) flaw in backend module
It was discovered that, when loading XML/RSDL documents, the oVirt Engine back end module used an insecure DocumentBuilderFactory. A remote, authenticated attacker could use this flaw to read files accessible to the user running the ovirt-engine server, and potentially perform other more advanced XML External Entity (XXE) attacks.

Find out more about CVE-2014-3573 from the MITRE CVE dictionary dictionary and NIST NVD.

CVSS v2 metrics

Base Score 4
Base Metrics AV:N/AC:L/Au:S/C:P/I:N/A:N
Access Vector Network
Access Complexity Low
Authentication Single
Confidentiality Impact Partial
Integrity Impact None
Availability Impact None

Find out more about Red Hat support for the Common Vulnerability Scoring System (CVSS).

Red Hat Security Errata

Platform Errata Release Date
RHEV Manager 3 (org.ovirt.engine-root) RHSA-2014:1161 2014-09-04

Affected Packages State

Platform Package State
Red Hat Gluster Storage 3.0 org.ovirt.engine-root Will not fix
Red Hat Gluster Storage 2.1 org.ovirt.engine-root Will not fix
RHEV Manager 3 ovirt-engine-backend Will not fix

Acknowledgements

This issue was discovered by Arun Babu Neelicattu of Red Hat Product Security.

Last Modified
Close

Welcome! Check out the Getting Started with Red Hat page for quick tours and guides for common tasks.