Описание
Apache Tomcat before 6.0.40, 7.x before 7.0.54, and 8.x before 8.0.6 does not properly constrain the class loader that accesses the XML parser used with an XSLT stylesheet, which allows remote attackers to (1) read arbitrary files via a crafted web application that provides an XML external entity declaration in conjunction with an entity reference, related to an XML External Entity (XXE) issue, or (2) read files associated with different web applications on a single Tomcat instance via a crafted web application.
It was found that, in certain circumstances, it was possible for a malicious web application to replace the XML parsers used by JBoss Web / Apache Tomcat to process XSLTs for the default servlet, JSP documents, tag library descriptors (TLDs), and tag plug-in configuration files. The injected XML parser(s) could then bypass the limits imposed on XML external entities and/or gain access to the XML files processed for other web applications deployed on the same JBoss Web / Apache Tomcat instance.
Затронутые пакеты
Платформа | Пакет | Состояние | Рекомендация | Релиз |
---|---|---|---|---|
Red Hat Developer Toolset 2.0 | devtoolset-2-tomcat | Not affected | ||
Red Hat Enterprise Linux 5 | tomcat5 | Will not fix | ||
Red Hat JBoss Enterprise Application Platform 5 | jbossweb | Will not fix | ||
Red Hat JBoss Enterprise Web Server 1 | others | Will not fix | ||
Red Hat JBoss Enterprise Web Server 1 | tomcat5 | Will not fix | ||
Red Hat JBoss Enterprise Web Server 1 | tomcat6 | Will not fix | ||
Red Hat JBoss Operations Network 3 | jbossweb | Affected | ||
Red Hat Enterprise Linux 6 | tomcat6 | Fixed | RHSA-2014:1038 | 11.08.2014 |
Red Hat Enterprise Linux 7 | tomcat | Fixed | RHSA-2014:1034 | 07.08.2014 |
Red Hat JBoss BPMS 6.0 | jbossweb | Fixed | RHSA-2015:0234 | 17.02.2015 |
Показывать по
Дополнительная информация
Статус:
EPSS
2.1 Low
CVSS2
Связанные уязвимости
Apache Tomcat before 6.0.40, 7.x before 7.0.54, and 8.x before 8.0.6 does not properly constrain the class loader that accesses the XML parser used with an XSLT stylesheet, which allows remote attackers to (1) read arbitrary files via a crafted web application that provides an XML external entity declaration in conjunction with an entity reference, related to an XML External Entity (XXE) issue, or (2) read files associated with different web applications on a single Tomcat instance via a crafted web application.
Apache Tomcat before 6.0.40, 7.x before 7.0.54, and 8.x before 8.0.6 does not properly constrain the class loader that accesses the XML parser used with an XSLT stylesheet, which allows remote attackers to (1) read arbitrary files via a crafted web application that provides an XML external entity declaration in conjunction with an entity reference, related to an XML External Entity (XXE) issue, or (2) read files associated with different web applications on a single Tomcat instance via a crafted web application.
Apache Tomcat before 6.0.40, 7.x before 7.0.54, and 8.x before 8.0.6 d ...
EPSS
2.1 Low
CVSS2