An External XML entity (XXE) vulnerability in ePO prior to 5.10 Update 14 can lead to an unauthenticated remote attacker to potentially trigger a Server Side Request Forgery attack. This can be exploited by mimicking the Agent Handler call to ePO and passing the carefully constructed XML file through the API.
Metrics
Affected Vendors & Products
References
History
No history.
MITRE
Status: PUBLISHED
Assigner: trellix
Published: 2022-10-18T00:00:00
Updated: 2024-08-03T01:07:06.476Z
Reserved: 2022-09-27T00:00:00
Link: CVE-2022-3338
Vulnrichment
No data.
NVD
Status : Modified
Published: 2022-10-18T10:15:10.637
Modified: 2024-11-21T07:19:19.557
Link: CVE-2022-3338
Redhat
No data.