RULE(RULE ID:315674)

Rule General Information
Release Date: 2015-03-20
Rule Name: Mcafee Epolicy Orchestrator XML External Entity Vulnerability -1 (CVE-2014-2205)
Severity:
CVE ID:
Rule Protection Details
Description: The Import and Export Framework in McAfee ePolicy Orchestrator (ePO) before 4.6.7 Hotfix 940148 allows remote authenticated users with permissions to add dashboards to read arbitrary files by importing a crafted XML file, related to an XML External Entity (XXE) issue.
Impact: An attacker can abtain sensitive information of the target victim, and do malicious actions to gain profits using the information.
Affected OS: Windows
Reference: SecurityFocusBID:65771
Solutions
More advisories have been published on the website, please visit for more suggestions:
https://kc.mcafee.com/corporate/index?page=content&