Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2014-0119

Опубликовано: 31 мая 2014
Источник: ubuntu
Приоритет: low
EPSS Низкий
CVSS2: 4.3

Описание

Apache Tomcat before 6.0.40, 7.x before 7.0.54, and 8.x before 8.0.6 does not properly constrain the class loader that accesses the XML parser used with an XSLT stylesheet, which allows remote attackers to (1) read arbitrary files via a crafted web application that provides an XML external entity declaration in conjunction with an entity reference, related to an XML External Entity (XXE) issue, or (2) read files associated with different web applications on a single Tomcat instance via a crafted web application.

РелизСтатусПримечание
artful

DNE

bionic

DNE

cosmic

DNE

devel

DNE

disco

DNE

eoan

DNE

esm-apps/xenial

not-affected

6.0.41-1
esm-infra-legacy/trusty

not-affected

6.0.39-1ubuntu0.1
esm-infra/focal

DNE

focal

DNE

Показывать по

РелизСтатусПримечание
artful

not-affected

7.0.53-1
bionic

not-affected

7.0.53-1
cosmic

not-affected

7.0.53-1
devel

DNE

disco

DNE

eoan

DNE

esm-apps/bionic

not-affected

7.0.53-1
esm-apps/xenial

not-affected

7.0.53-1
esm-infra-legacy/trusty

not-affected

7.0.52-1ubuntu0.3
esm-infra/focal

DNE

Показывать по

РелизСтатусПримечание
artful

not-affected

8.0.9-1
bionic

not-affected

8.0.9-1
cosmic

not-affected

8.0.9-1
devel

DNE

disco

DNE

eoan

DNE

esm-apps/bionic

not-affected

8.0.9-1
esm-infra-legacy/trusty

DNE

esm-infra/focal

DNE

esm-infra/xenial

not-affected

8.0.9-1

Показывать по

EPSS

Процентиль: 90%
0.05441
Низкий

4.3 Medium

CVSS2

Связанные уязвимости

redhat
около 11 лет назад

Apache Tomcat before 6.0.40, 7.x before 7.0.54, and 8.x before 8.0.6 does not properly constrain the class loader that accesses the XML parser used with an XSLT stylesheet, which allows remote attackers to (1) read arbitrary files via a crafted web application that provides an XML external entity declaration in conjunction with an entity reference, related to an XML External Entity (XXE) issue, or (2) read files associated with different web applications on a single Tomcat instance via a crafted web application.

nvd
около 11 лет назад

Apache Tomcat before 6.0.40, 7.x before 7.0.54, and 8.x before 8.0.6 does not properly constrain the class loader that accesses the XML parser used with an XSLT stylesheet, which allows remote attackers to (1) read arbitrary files via a crafted web application that provides an XML external entity declaration in conjunction with an entity reference, related to an XML External Entity (XXE) issue, or (2) read files associated with different web applications on a single Tomcat instance via a crafted web application.

debian
около 11 лет назад

Apache Tomcat before 6.0.40, 7.x before 7.0.54, and 8.x before 8.0.6 d ...

github
около 3 лет назад

Missing XML Validation in Apache Tomcat

oracle-oval
почти 11 лет назад

ELSA-2014-1034: tomcat security update (LOW)

EPSS

Процентиль: 90%
0.05441
Низкий

4.3 Medium

CVSS2

Уязвимость CVE-2014-0119