It was found that the ovirt-engine REST API would resolve entities in XML API calls. A remote attacker with credentials to call the ovirt-engine REST API could use this flaw to read files accessible to the user running the ovirt-engine JBoss server, and potentially perform other more advanced XXE attacks.
Acknowledgements: This issue was discovered by David Jorm of Red Hat Product Security.
This issue has been addressed in following products: RHEV Manager version 3.4 Via RHSA-2014:0814 https://rhn.redhat.com/errata/RHSA-2014-0814.html