CVE Vulnerabilities

CVE-2014-0096

Published: May 31, 2014 | Modified: Apr 12, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
4.3 MEDIUM
AV:N/AC:M/Au:N/C:P/I:N/A:N
RedHat/V2
2.1 LOW
AV:N/AC:H/Au:S/C:P/I:N/A:N
RedHat/V3
Ubuntu
MEDIUM
root.io logo minimus.io logo echo.ai logo

java/org/apache/catalina/servlets/DefaultServlet.java in the default servlet in Apache Tomcat before 6.0.40, 7.x before 7.0.53, and 8.x before 8.0.4 does not properly restrict XSLT stylesheets, which allows remote attackers to bypass security-manager restrictions and read arbitrary files via a crafted web application that provides an XML external entity declaration in conjunction with an entity reference, related to an XML External Entity (XXE) issue.

Affected Software

NameVendorStart VersionEnd Version
TomcatApache7.0.0 (including)7.0.0 (including)
TomcatApache7.0.0-beta (including)7.0.0-beta (including)
TomcatApache7.0.1 (including)7.0.1 (including)
TomcatApache7.0.2 (including)7.0.2 (including)
TomcatApache7.0.2-beta (including)7.0.2-beta (including)
TomcatApache7.0.3 (including)7.0.3 (including)
TomcatApache7.0.4 (including)7.0.4 (including)
TomcatApache7.0.4-beta (including)7.0.4-beta (including)
TomcatApache7.0.5 (including)7.0.5 (including)
TomcatApache7.0.6 (including)7.0.6 (including)
TomcatApache7.0.7 (including)7.0.7 (including)
TomcatApache7.0.8 (including)7.0.8 (including)
TomcatApache7.0.9 (including)7.0.9 (including)
TomcatApache7.0.10 (including)7.0.10 (including)
TomcatApache7.0.11 (including)7.0.11 (including)
TomcatApache7.0.12 (including)7.0.12 (including)
TomcatApache7.0.13 (including)7.0.13 (including)
TomcatApache7.0.14 (including)7.0.14 (including)
TomcatApache7.0.15 (including)7.0.15 (including)
TomcatApache7.0.16 (including)7.0.16 (including)
TomcatApache7.0.17 (including)7.0.17 (including)
TomcatApache7.0.18 (including)7.0.18 (including)
TomcatApache7.0.19 (including)7.0.19 (including)
TomcatApache7.0.20 (including)7.0.20 (including)
TomcatApache7.0.21 (including)7.0.21 (including)
TomcatApache7.0.22 (including)7.0.22 (including)
TomcatApache7.0.23 (including)7.0.23 (including)
TomcatApache7.0.24 (including)7.0.24 (including)
TomcatApache7.0.25 (including)7.0.25 (including)
TomcatApache7.0.26 (including)7.0.26 (including)
TomcatApache7.0.27 (including)7.0.27 (including)
TomcatApache7.0.28 (including)7.0.28 (including)
TomcatApache7.0.29 (including)7.0.29 (including)
TomcatApache7.0.30 (including)7.0.30 (including)
TomcatApache7.0.31 (including)7.0.31 (including)
TomcatApache7.0.32 (including)7.0.32 (including)
TomcatApache7.0.33 (including)7.0.33 (including)
TomcatApache7.0.34 (including)7.0.34 (including)
TomcatApache7.0.35 (including)7.0.35 (including)
TomcatApache7.0.36 (including)7.0.36 (including)
TomcatApache7.0.37 (including)7.0.37 (including)
TomcatApache7.0.38 (including)7.0.38 (including)
TomcatApache7.0.39 (including)7.0.39 (including)
TomcatApache7.0.40 (including)7.0.40 (including)
TomcatApache7.0.41 (including)7.0.41 (including)
TomcatApache7.0.42 (including)7.0.42 (including)
TomcatApache7.0.43 (including)7.0.43 (including)
TomcatApache7.0.44 (including)7.0.44 (including)
TomcatApache7.0.45 (including)7.0.45 (including)
TomcatApache7.0.46 (including)7.0.46 (including)
TomcatApache7.0.47 (including)7.0.47 (including)
TomcatApache7.0.48 (including)7.0.48 (including)
TomcatApache7.0.49 (including)7.0.49 (including)
TomcatApache7.0.50 (including)7.0.50 (including)
TomcatApache7.0.52 (including)7.0.52 (including)
Red Hat Enterprise Linux 6RedHattomcat6-0:6.0.24-72.el6_5*
Red Hat Enterprise Linux 7RedHattomcat-0:7.0.42-6.el7_0*
Red Hat JBoss BPMS 6.0RedHatjbossweb*
Red Hat JBoss BRMS 6.0RedHatjbossweb*
Red Hat JBoss Data Grid 6.3RedHatjbossweb*
Red Hat JBoss Data Virtualization 6.0RedHatjbossweb*
Red Hat JBoss Data Virtualization 6.1RedHat*
Red Hat JBoss Enterprise Application Platform 6.2RedHat*
Red Hat JBoss Enterprise Application Platform 6.2 for RHEL 5RedHatjbossweb-0:7.3.2-4.Final_redhat_3.1.ep6.el5*
Red Hat JBoss Enterprise Application Platform 6.2 for RHEL 6RedHatjbossweb-0:7.3.2-4.Final_redhat_3.1.ep6.el6*
Red Hat JBoss Enterprise Web Server 2 for RHEL 5RedHattomcat6-0:6.0.37-20_patch_04.ep6.el5*
Red Hat JBoss Enterprise Web Server 2 for RHEL 5RedHattomcat7-0:7.0.40-14_patch_03.ep6.el5*
Red Hat JBoss Enterprise Web Server 2 for RHEL 6RedHattomcat6-0:6.0.37-29_patch_05.ep6.el6*
Red Hat JBoss Enterprise Web Server 2 for RHEL 6RedHattomcat7-0:7.0.40-11_patch_03.ep6.el6*
Red Hat JBoss Fuse Service Works 6.0RedHatjbossweb*
Red Hat JBoss Portal 6.2RedHatjbossweb*
Red Hat JBoss Web Server 2.0RedHattomcat6*
Red Hat JBoss Web Server 2.0RedHattomcat7*
Tomcat6Ubuntuesm-infra-legacy/trusty*
Tomcat6Ubuntulucid*
Tomcat6Ubuntuprecise*
Tomcat6Ubuntusaucy*
Tomcat6Ubuntutrusty*
Tomcat6Ubuntutrusty/esm*
Tomcat6Ubuntuupstream*
Tomcat7Ubuntuesm-infra-legacy/trusty*
Tomcat7Ubuntuprecise*
Tomcat7Ubuntusaucy*
Tomcat7Ubuntutrusty*
Tomcat7Ubuntutrusty/esm*
Tomcat7Ubuntuupstream*
Tomcat8Ubuntuupstream*

References