Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2014-0096

Опубликовано: 31 мая 2014
Источник: ubuntu
Приоритет: medium
EPSS Низкий
CVSS2: 4.3

Описание

java/org/apache/catalina/servlets/DefaultServlet.java in the default servlet in Apache Tomcat before 6.0.40, 7.x before 7.0.53, and 8.x before 8.0.4 does not properly restrict XSLT stylesheets, which allows remote attackers to bypass security-manager restrictions and read arbitrary files via a crafted web application that provides an XML external entity declaration in conjunction with an entity reference, related to an XML External Entity (XXE) issue.

РелизСтатусПримечание
artful

DNE

bionic

DNE

devel

DNE

esm-apps/xenial

not-affected

6.0.41-1
esm-infra-legacy/trusty

not-affected

6.0.39-1ubuntu0.1
lucid

released

6.0.24-2ubuntu1.16
precise

released

6.0.35-1ubuntu3.5
precise/esm

not-affected

6.0.35-1ubuntu3.5
saucy

ignored

end of life
trusty

released

6.0.39-1ubuntu0.1

Показывать по

РелизСтатусПримечание
artful

not-affected

7.0.53-1
bionic

not-affected

7.0.53-1
devel

not-affected

7.0.53-1
esm-apps/bionic

not-affected

7.0.53-1
esm-apps/xenial

not-affected

7.0.53-1
esm-infra-legacy/trusty

not-affected

7.0.52-1ubuntu0.1
lucid

DNE

precise

ignored

end of life
precise/esm

DNE

precise was needed
saucy

ignored

end of life

Показывать по

РелизСтатусПримечание
artful

not-affected

8.0.9-1
bionic

not-affected

8.0.9-1
devel

not-affected

8.0.9-1
esm-apps/bionic

not-affected

8.0.9-1
esm-infra-legacy/trusty

DNE

esm-infra/xenial

not-affected

8.0.9-1
lucid

DNE

precise

DNE

precise/esm

DNE

saucy

DNE

Показывать по

EPSS

Процентиль: 81%
0.01617
Низкий

4.3 Medium

CVSS2

Связанные уязвимости

redhat
около 11 лет назад

java/org/apache/catalina/servlets/DefaultServlet.java in the default servlet in Apache Tomcat before 6.0.40, 7.x before 7.0.53, and 8.x before 8.0.4 does not properly restrict XSLT stylesheets, which allows remote attackers to bypass security-manager restrictions and read arbitrary files via a crafted web application that provides an XML external entity declaration in conjunction with an entity reference, related to an XML External Entity (XXE) issue.

nvd
около 11 лет назад

java/org/apache/catalina/servlets/DefaultServlet.java in the default servlet in Apache Tomcat before 6.0.40, 7.x before 7.0.53, and 8.x before 8.0.4 does not properly restrict XSLT stylesheets, which allows remote attackers to bypass security-manager restrictions and read arbitrary files via a crafted web application that provides an XML external entity declaration in conjunction with an entity reference, related to an XML External Entity (XXE) issue.

debian
около 11 лет назад

java/org/apache/catalina/servlets/DefaultServlet.java in the default s ...

github
около 3 лет назад

Improper Input Validation in Apache Tomcat

fstec
около 11 лет назад

Уязвимость программного обеспечения Apache Tomcat, позволяющая удаленному злоумышленнику нарушить конфиденциальность защищаемой информации

EPSS

Процентиль: 81%
0.01617
Низкий

4.3 Medium

CVSS2