CVE Vulnerabilities

CVE-2014-0096

Published: May 31, 2014 | Modified: Nov 07, 2023
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
4.3 MEDIUM
AV:N/AC:M/Au:N/C:P/I:N/A:N
RedHat/V2
2.1 LOW
AV:N/AC:H/Au:S/C:P/I:N/A:N
RedHat/V3
Ubuntu
MEDIUM

java/org/apache/catalina/servlets/DefaultServlet.java in the default servlet in Apache Tomcat before 6.0.40, 7.x before 7.0.53, and 8.x before 8.0.4 does not properly restrict XSLT stylesheets, which allows remote attackers to bypass security-manager restrictions and read arbitrary files via a crafted web application that provides an XML external entity declaration in conjunction with an entity reference, related to an XML External Entity (XXE) issue.

Affected Software

Name Vendor Start Version End Version
Tomcat Apache 7.0.0 (including) 7.0.0 (including)
Tomcat Apache 7.0.0-beta (including) 7.0.0-beta (including)
Tomcat Apache 7.0.1 (including) 7.0.1 (including)
Tomcat Apache 7.0.2 (including) 7.0.2 (including)
Tomcat Apache 7.0.2-beta (including) 7.0.2-beta (including)
Tomcat Apache 7.0.3 (including) 7.0.3 (including)
Tomcat Apache 7.0.4 (including) 7.0.4 (including)
Tomcat Apache 7.0.4-beta (including) 7.0.4-beta (including)
Tomcat Apache 7.0.5 (including) 7.0.5 (including)
Tomcat Apache 7.0.6 (including) 7.0.6 (including)
Tomcat Apache 7.0.7 (including) 7.0.7 (including)
Tomcat Apache 7.0.8 (including) 7.0.8 (including)
Tomcat Apache 7.0.9 (including) 7.0.9 (including)
Tomcat Apache 7.0.10 (including) 7.0.10 (including)
Tomcat Apache 7.0.11 (including) 7.0.11 (including)
Tomcat Apache 7.0.12 (including) 7.0.12 (including)
Tomcat Apache 7.0.13 (including) 7.0.13 (including)
Tomcat Apache 7.0.14 (including) 7.0.14 (including)
Tomcat Apache 7.0.15 (including) 7.0.15 (including)
Tomcat Apache 7.0.16 (including) 7.0.16 (including)
Tomcat Apache 7.0.17 (including) 7.0.17 (including)
Tomcat Apache 7.0.18 (including) 7.0.18 (including)
Tomcat Apache 7.0.19 (including) 7.0.19 (including)
Tomcat Apache 7.0.20 (including) 7.0.20 (including)
Tomcat Apache 7.0.21 (including) 7.0.21 (including)
Tomcat Apache 7.0.22 (including) 7.0.22 (including)
Tomcat Apache 7.0.23 (including) 7.0.23 (including)
Tomcat Apache 7.0.24 (including) 7.0.24 (including)
Tomcat Apache 7.0.25 (including) 7.0.25 (including)
Tomcat Apache 7.0.26 (including) 7.0.26 (including)
Tomcat Apache 7.0.27 (including) 7.0.27 (including)
Tomcat Apache 7.0.28 (including) 7.0.28 (including)
Tomcat Apache 7.0.29 (including) 7.0.29 (including)
Tomcat Apache 7.0.30 (including) 7.0.30 (including)
Tomcat Apache 7.0.31 (including) 7.0.31 (including)
Tomcat Apache 7.0.32 (including) 7.0.32 (including)
Tomcat Apache 7.0.33 (including) 7.0.33 (including)
Tomcat Apache 7.0.34 (including) 7.0.34 (including)
Tomcat Apache 7.0.35 (including) 7.0.35 (including)
Tomcat Apache 7.0.36 (including) 7.0.36 (including)
Tomcat Apache 7.0.37 (including) 7.0.37 (including)
Tomcat Apache 7.0.38 (including) 7.0.38 (including)
Tomcat Apache 7.0.39 (including) 7.0.39 (including)
Tomcat Apache 7.0.40 (including) 7.0.40 (including)
Tomcat Apache 7.0.41 (including) 7.0.41 (including)
Tomcat Apache 7.0.42 (including) 7.0.42 (including)
Tomcat Apache 7.0.43 (including) 7.0.43 (including)
Tomcat Apache 7.0.44 (including) 7.0.44 (including)
Tomcat Apache 7.0.45 (including) 7.0.45 (including)
Tomcat Apache 7.0.46 (including) 7.0.46 (including)
Tomcat Apache 7.0.47 (including) 7.0.47 (including)
Tomcat Apache 7.0.48 (including) 7.0.48 (including)
Tomcat Apache 7.0.49 (including) 7.0.49 (including)
Tomcat Apache 7.0.50 (including) 7.0.50 (including)
Tomcat Apache 7.0.52 (including) 7.0.52 (including)
Red Hat Enterprise Linux 6 RedHat tomcat6-0:6.0.24-72.el6_5 *
Red Hat Enterprise Linux 7 RedHat tomcat-0:7.0.42-6.el7_0 *
Red Hat JBoss BPMS 6.0 RedHat jbossweb *
Red Hat JBoss BRMS 6.0 RedHat jbossweb *
Red Hat JBoss Data Grid 6.3 RedHat jbossweb *
Red Hat JBoss Data Virtualization 6.0 RedHat jbossweb *
Red Hat JBoss Data Virtualization 6.1 RedHat *
Red Hat JBoss Enterprise Application Platform 6.2 RedHat *
Red Hat JBoss Enterprise Application Platform 6.2 for RHEL 5 RedHat jbossweb-0:7.3.2-4.Final_redhat_3.1.ep6.el5 *
Red Hat JBoss Enterprise Application Platform 6.2 for RHEL 6 RedHat jbossweb-0:7.3.2-4.Final_redhat_3.1.ep6.el6 *
Red Hat JBoss Enterprise Web Server 2 for RHEL 5 RedHat tomcat6-0:6.0.37-20_patch_04.ep6.el5 *
Red Hat JBoss Enterprise Web Server 2 for RHEL 5 RedHat tomcat7-0:7.0.40-14_patch_03.ep6.el5 *
Red Hat JBoss Enterprise Web Server 2 for RHEL 6 RedHat tomcat6-0:6.0.37-29_patch_05.ep6.el6 *
Red Hat JBoss Enterprise Web Server 2 for RHEL 6 RedHat tomcat7-0:7.0.40-11_patch_03.ep6.el6 *
Red Hat JBoss Fuse Service Works 6.0 RedHat jbossweb *
Red Hat JBoss Portal 6.2 RedHat jbossweb *
Red Hat JBoss Web Server 2.0 RedHat tomcat6 *
Red Hat JBoss Web Server 2.0 RedHat tomcat7 *
Tomcat6 Ubuntu lucid *
Tomcat6 Ubuntu precise *
Tomcat6 Ubuntu saucy *
Tomcat6 Ubuntu trusty *
Tomcat6 Ubuntu upstream *
Tomcat7 Ubuntu precise *
Tomcat7 Ubuntu saucy *
Tomcat7 Ubuntu trusty *
Tomcat7 Ubuntu upstream *
Tomcat8 Ubuntu upstream *

References