CVE Vulnerabilities

CVE-2022-3338

Improper Restriction of XML External Entity Reference

Published: Oct 18, 2022 | Modified: Nov 21, 2024
CVSS 3.x
5.4
MEDIUM
Source:
NVD
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:L/I:L/A:N
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu
root.io logo minimus.io logo echo.ai logo

An External XML entity (XXE) vulnerability in ePO prior to 5.10 Update 14 can lead to an unauthenticated remote attacker to potentially trigger a Server Side Request Forgery attack. This can be exploited by mimicking the Agent Handler call to ePO and passing the carefully constructed XML file through the API.

Weakness

The product processes an XML document that can contain XML entities with URIs that resolve to documents outside of the intended sphere of control, causing the product to embed incorrect documents into its output.

Affected Software

NameVendorStart VersionEnd Version
Epolicy_orchestratorMcafee*5.10.0 (excluding)
Epolicy_orchestratorMcafee5.10.0 (including)5.10.0 (including)
Epolicy_orchestratorMcafee5.10.0-update_1 (including)5.10.0-update_1 (including)
Epolicy_orchestratorMcafee5.10.0-update_10 (including)5.10.0-update_10 (including)
Epolicy_orchestratorMcafee5.10.0-update_11 (including)5.10.0-update_11 (including)
Epolicy_orchestratorMcafee5.10.0-update_12 (including)5.10.0-update_12 (including)
Epolicy_orchestratorMcafee5.10.0-update_13 (including)5.10.0-update_13 (including)
Epolicy_orchestratorMcafee5.10.0-update_2 (including)5.10.0-update_2 (including)
Epolicy_orchestratorMcafee5.10.0-update_3 (including)5.10.0-update_3 (including)
Epolicy_orchestratorMcafee5.10.0-update_4 (including)5.10.0-update_4 (including)
Epolicy_orchestratorMcafee5.10.0-update_5 (including)5.10.0-update_5 (including)
Epolicy_orchestratorMcafee5.10.0-update_6 (including)5.10.0-update_6 (including)
Epolicy_orchestratorMcafee5.10.0-update_7 (including)5.10.0-update_7 (including)
Epolicy_orchestratorMcafee5.10.0-update_8 (including)5.10.0-update_8 (including)
Epolicy_orchestratorMcafee5.10.0-update_9 (including)5.10.0-update_9 (including)

Potential Mitigations

References