Bugzilla will be upgraded to version 5.0 on a still to be determined date in the near future. The original upgrade date has been delayed.
Bug 1164083 - (CVE-2014-5325) CVE-2014-5325 dwr: XML external entity injection (JVN#91502163)
CVE-2014-5325 dwr: XML external entity injection (JVN#91502163)
Status: NEW
Product: Security Response
Classification: Other
Component: vulnerability (Show other bugs)
unspecified
All Linux
medium Severity medium
: ---
: ---
Assigned To: Red Hat Product Security
impact=moderate,public=20141114,repor...
: Security
Depends On:
Blocks: 1164085 1181470
  Show dependency treegraph
 
Reported: 2014-11-13 23:27 EST by Murray McAllister
Modified: 2018-01-30 10:43 EST (History)
1 user (show)

See Also:
Fixed In Version:
Doc Type: Bug Fix
Doc Text:
Story Points: ---
Clone Of:
Environment:
Last Closed:
Type: ---
Regression: ---
Mount Type: ---
Documentation: ---
CRM:
Verified Versions:
Category: ---
oVirt Team: ---
RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: ---


Attachments (Terms of Use)

  None (edit)
Description Murray McAllister 2014-11-13 23:27:35 EST
It was reported that Direct Web Remoting (DWR) is vulnerable to an XML External Entity (XXE) injection flaw. This could possibly be used to read an arbitrary file or possibly perform more advanced XXE attacks.

DWR is used in Red Hat Satellite Server 5.6; however, it is not yet clear whether the affected functionality is exposed in that product or not.

Reference:
http://jvn.jp/en/jp/JVN91502163/

Note You need to log in before you can comment on or make changes to this bug.