Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2014-0107

Опубликовано: 15 апр. 2014
Источник: ubuntu
Приоритет: medium
EPSS Низкий
CVSS2: 7.5

Описание

The TransformerFactory in Apache Xalan-Java before 2.7.2 does not properly restrict access to certain properties when FEATURE_SECURE_PROCESSING is enabled, which allows remote attackers to bypass expected restrictions and load arbitrary classes or access external resources via a crafted (1) xalan:content-header, (2) xalan:entities, (3) xslt:content-header, or (4) xslt:entities property, or a Java property that is bound to the XSLT 1.0 system-property function.

РелизСтатусПримечание
devel

not-affected

2.7.1-9
esm-infra-legacy/trusty

not-affected

2.7.1-9
lucid

released

2.7.1-5ubuntu1.1
precise

released

2.7.1-7ubuntu0.1
quantal

ignored

end of life
saucy

released

2.7.1-8ubuntu0.1
trusty

not-affected

2.7.1-9
trusty/esm

not-affected

2.7.1-9
upstream

released

2.7.1-9

Показывать по

EPSS

Процентиль: 90%
0.05673
Низкий

7.5 High

CVSS2

Связанные уязвимости

redhat
больше 11 лет назад

The TransformerFactory in Apache Xalan-Java before 2.7.2 does not properly restrict access to certain properties when FEATURE_SECURE_PROCESSING is enabled, which allows remote attackers to bypass expected restrictions and load arbitrary classes or access external resources via a crafted (1) xalan:content-header, (2) xalan:entities, (3) xslt:content-header, or (4) xslt:entities property, or a Java property that is bound to the XSLT 1.0 system-property function.

nvd
больше 11 лет назад

The TransformerFactory in Apache Xalan-Java before 2.7.2 does not properly restrict access to certain properties when FEATURE_SECURE_PROCESSING is enabled, which allows remote attackers to bypass expected restrictions and load arbitrary classes or access external resources via a crafted (1) xalan:content-header, (2) xalan:entities, (3) xslt:content-header, or (4) xslt:entities property, or a Java property that is bound to the XSLT 1.0 system-property function.

debian
больше 11 лет назад

The TransformerFactory in Apache Xalan-Java before 2.7.2 does not prop ...

github
больше 3 лет назад

Improper Authorization in Apache Xalan-Java

oracle-oval
больше 11 лет назад

ELSA-2014-0348: xalan-j2 security update (IMPORTANT)

EPSS

Процентиль: 90%
0.05673
Низкий

7.5 High

CVSS2