CVE Vulnerabilities

CVE-2022-3338

Improper Restriction of XML External Entity Reference

Published: Oct 18, 2022 | Modified: Nov 21, 2024
CVSS 3.x
5.4
MEDIUM
Source:
NVD
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:L/I:L/A:N
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu

An External XML entity (XXE) vulnerability in ePO prior to 5.10 Update 14 can lead to an unauthenticated remote attacker to potentially trigger a Server Side Request Forgery attack. This can be exploited by mimicking the Agent Handler call to ePO and passing the carefully constructed XML file through the API.

Weakness

The product processes an XML document that can contain XML entities with URIs that resolve to documents outside of the intended sphere of control, causing the product to embed incorrect documents into its output.

Affected Software

Name Vendor Start Version End Version
Epolicy_orchestrator Mcafee * 5.10.0 (excluding)
Epolicy_orchestrator Mcafee 5.10.0 (including) 5.10.0 (including)
Epolicy_orchestrator Mcafee 5.10.0-update_1 (including) 5.10.0-update_1 (including)
Epolicy_orchestrator Mcafee 5.10.0-update_10 (including) 5.10.0-update_10 (including)
Epolicy_orchestrator Mcafee 5.10.0-update_11 (including) 5.10.0-update_11 (including)
Epolicy_orchestrator Mcafee 5.10.0-update_12 (including) 5.10.0-update_12 (including)
Epolicy_orchestrator Mcafee 5.10.0-update_13 (including) 5.10.0-update_13 (including)
Epolicy_orchestrator Mcafee 5.10.0-update_2 (including) 5.10.0-update_2 (including)
Epolicy_orchestrator Mcafee 5.10.0-update_3 (including) 5.10.0-update_3 (including)
Epolicy_orchestrator Mcafee 5.10.0-update_4 (including) 5.10.0-update_4 (including)
Epolicy_orchestrator Mcafee 5.10.0-update_5 (including) 5.10.0-update_5 (including)
Epolicy_orchestrator Mcafee 5.10.0-update_6 (including) 5.10.0-update_6 (including)
Epolicy_orchestrator Mcafee 5.10.0-update_7 (including) 5.10.0-update_7 (including)
Epolicy_orchestrator Mcafee 5.10.0-update_8 (including) 5.10.0-update_8 (including)
Epolicy_orchestrator Mcafee 5.10.0-update_9 (including) 5.10.0-update_9 (including)

Potential Mitigations

References