Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2014-0107

Опубликовано: 24 мар. 2014
Источник: redhat
CVSS2: 6.8
EPSS Низкий

Описание

The TransformerFactory in Apache Xalan-Java before 2.7.2 does not properly restrict access to certain properties when FEATURE_SECURE_PROCESSING is enabled, which allows remote attackers to bypass expected restrictions and load arbitrary classes or access external resources via a crafted (1) xalan:content-header, (2) xalan:entities, (3) xslt:content-header, or (4) xslt:entities property, or a Java property that is bound to the XSLT 1.0 system-property function.

It was found that the secure processing feature of Xalan-Java had insufficient restrictions defined for certain properties and features. A remote attacker able to provide Extensible Stylesheet Language Transformations (XSLT) content to be processed by an application using Xalan-Java could use this flaw to bypass the intended constraints of the secure processing feature. Depending on the components available in the classpath, this could lead to arbitrary remote code execution in the context of the application server running the application that uses Xalan-Java.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 7xalan-j2Not affected
Red Hat Enterprise Virtualization 3jasperreports-server-proNot affected
Red Hat JBoss Data Grid 6xalan-j2Not affected
Red Hat JBoss Data Virtualization 6xalan-j2Not affected
Red Hat JBoss Enterprise Application Platform 4xalan-j2Will not fix
Red Hat JBoss Enterprise Web Server 1amq-6.0Affected
Red Hat JBoss Enterprise Web Server 1fuse-6.0Affected
Red Hat JBoss Enterprise Web Server 1fuse-esb-7.1Affected
Red Hat JBoss Enterprise Web Server 1fuse-mq-7.1Affected
Red Hat JBoss Enterprise Web Server 1xalan-j2Affected

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-358
https://bugzilla.redhat.com/show_bug.cgi?id=1080248Xalan-Java: insufficient constraints in secure processing feature

EPSS

Процентиль: 91%
0.06467
Низкий

6.8 Medium

CVSS2

Связанные уязвимости

ubuntu
больше 11 лет назад

The TransformerFactory in Apache Xalan-Java before 2.7.2 does not properly restrict access to certain properties when FEATURE_SECURE_PROCESSING is enabled, which allows remote attackers to bypass expected restrictions and load arbitrary classes or access external resources via a crafted (1) xalan:content-header, (2) xalan:entities, (3) xslt:content-header, or (4) xslt:entities property, or a Java property that is bound to the XSLT 1.0 system-property function.

nvd
больше 11 лет назад

The TransformerFactory in Apache Xalan-Java before 2.7.2 does not properly restrict access to certain properties when FEATURE_SECURE_PROCESSING is enabled, which allows remote attackers to bypass expected restrictions and load arbitrary classes or access external resources via a crafted (1) xalan:content-header, (2) xalan:entities, (3) xslt:content-header, or (4) xslt:entities property, or a Java property that is bound to the XSLT 1.0 system-property function.

debian
больше 11 лет назад

The TransformerFactory in Apache Xalan-Java before 2.7.2 does not prop ...

github
больше 3 лет назад

Improper Authorization in Apache Xalan-Java

oracle-oval
больше 11 лет назад

ELSA-2014-0348: xalan-j2 security update (IMPORTANT)

EPSS

Процентиль: 91%
0.06467
Низкий

6.8 Medium

CVSS2