CVE-2014-3485: Red Hat Enterprise Virtualization

Medium severity, CVSS 4.0. EPSS: 1.5% chance of exploitation in the next 30 days.

The REST API in the ovirt-engine in oVirt, as used in Red Hat Enterprise Virtualization (rhevm) 3.4, allows remote authenticated users to read arbitrary files and have other unspecified impact via unknown vectors, related to an XML External Entity (XXE) issue.

Affected products

  • Red Hat Enterprise Virtualization: version 3.4 only

Published 2014-07-11. Last modified 2026-06-17.