Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2014-0107

Опубликовано: 15 апр. 2014
Источник: nvd
CVSS2: 7.5
EPSS Низкий

Описание

The TransformerFactory in Apache Xalan-Java before 2.7.2 does not properly restrict access to certain properties when FEATURE_SECURE_PROCESSING is enabled, which allows remote attackers to bypass expected restrictions and load arbitrary classes or access external resources via a crafted (1) xalan:content-header, (2) xalan:entities, (3) xslt:content-header, or (4) xslt:entities property, or a Java property that is bound to the XSLT 1.0 system-property function.

Уязвимые конфигурации

Конфигурация 1

Одно из

cpe:2.3:a:apache:xalan-java:*:*:*:*:*:*:*:*
Версия до 2.7.1 (включая)
cpe:2.3:a:apache:xalan-java:1.0.0:*:*:*:*:*:*:*
cpe:2.3:a:apache:xalan-java:2.0.0:*:*:*:*:*:*:*
cpe:2.3:a:apache:xalan-java:2.0.1:*:*:*:*:*:*:*
cpe:2.3:a:apache:xalan-java:2.1.0:*:*:*:*:*:*:*
cpe:2.3:a:apache:xalan-java:2.2.0:*:*:*:*:*:*:*
cpe:2.3:a:apache:xalan-java:2.4.0:*:*:*:*:*:*:*
cpe:2.3:a:apache:xalan-java:2.4.1:*:*:*:*:*:*:*
cpe:2.3:a:apache:xalan-java:2.5.0:*:*:*:*:*:*:*
cpe:2.3:a:apache:xalan-java:2.5.1:*:*:*:*:*:*:*
cpe:2.3:a:apache:xalan-java:2.5.2:*:*:*:*:*:*:*
cpe:2.3:a:apache:xalan-java:2.6.0:*:*:*:*:*:*:*
cpe:2.3:a:apache:xalan-java:2.7.0:*:*:*:*:*:*:*
Конфигурация 2

Одно из

cpe:2.3:a:oracle:webcenter_sites:7.6.2:*:*:*:*:*:*:*
cpe:2.3:a:oracle:webcenter_sites:11.1.1.8.0:*:*:*:*:*:*:*

EPSS

Процентиль: 91%
0.06467
Низкий

7.5 High

CVSS2

Дефекты

CWE-264

Связанные уязвимости

ubuntu
больше 11 лет назад

The TransformerFactory in Apache Xalan-Java before 2.7.2 does not properly restrict access to certain properties when FEATURE_SECURE_PROCESSING is enabled, which allows remote attackers to bypass expected restrictions and load arbitrary classes or access external resources via a crafted (1) xalan:content-header, (2) xalan:entities, (3) xslt:content-header, or (4) xslt:entities property, or a Java property that is bound to the XSLT 1.0 system-property function.

redhat
больше 11 лет назад

The TransformerFactory in Apache Xalan-Java before 2.7.2 does not properly restrict access to certain properties when FEATURE_SECURE_PROCESSING is enabled, which allows remote attackers to bypass expected restrictions and load arbitrary classes or access external resources via a crafted (1) xalan:content-header, (2) xalan:entities, (3) xslt:content-header, or (4) xslt:entities property, or a Java property that is bound to the XSLT 1.0 system-property function.

debian
больше 11 лет назад

The TransformerFactory in Apache Xalan-Java before 2.7.2 does not prop ...

github
больше 3 лет назад

Improper Authorization in Apache Xalan-Java

oracle-oval
больше 11 лет назад

ELSA-2014-0348: xalan-j2 security update (IMPORTANT)

EPSS

Процентиль: 91%
0.06467
Низкий

7.5 High

CVSS2

Дефекты

CWE-264