CVE Vulnerabilities

CVE-2014-0119

Published: May 31, 2014 | Modified: Apr 12, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
4.3 MEDIUM
AV:N/AC:M/Au:N/C:P/I:N/A:N
RedHat/V2
2.1 LOW
AV:N/AC:H/Au:S/C:P/I:N/A:N
RedHat/V3
Ubuntu
LOW
root.io logo minimus.io logo echo.ai logo

Apache Tomcat before 6.0.40, 7.x before 7.0.54, and 8.x before 8.0.6 does not properly constrain the class loader that accesses the XML parser used with an XSLT stylesheet, which allows remote attackers to (1) read arbitrary files via a crafted web application that provides an XML external entity declaration in conjunction with an entity reference, related to an XML External Entity (XXE) issue, or (2) read files associated with different web applications on a single Tomcat instance via a crafted web application.

Affected Software

NameVendorStart VersionEnd Version
TomcatApache8.0.0-rc1 (including)8.0.0-rc1 (including)
TomcatApache8.0.0-rc10 (including)8.0.0-rc10 (including)
TomcatApache8.0.0-rc2 (including)8.0.0-rc2 (including)
TomcatApache8.0.0-rc5 (including)8.0.0-rc5 (including)
TomcatApache8.0.1 (including)8.0.1 (including)
TomcatApache8.0.3 (including)8.0.3 (including)
TomcatApache8.0.5 (including)8.0.5 (including)
Red Hat Enterprise Linux 6RedHattomcat6-0:6.0.24-78.el6_5*
Red Hat Enterprise Linux 7RedHattomcat-0:7.0.42-8.el7_0*
Red Hat JBoss BPMS 6.0RedHatjbossweb*
Red Hat JBoss BRMS 6.0RedHatjbossweb*
Red Hat JBoss Data Grid 6.3RedHatjbossweb*
Red Hat JBoss Data Virtualization 6.0RedHatjbossweb*
Red Hat JBoss Data Virtualization 6.1RedHat*
Red Hat JBoss Enterprise Application Platform 6.2RedHatjbossweb*
Red Hat JBoss Enterprise Application Platform 6.2 for RHEL 5RedHatjbossweb-0:7.3.2-4.Final_redhat_3.1.ep6.el5*
Red Hat JBoss Enterprise Application Platform 6.2 for RHEL 6RedHatjbossweb-0:7.3.2-4.Final_redhat_3.1.ep6.el6*
Red Hat JBoss Enterprise Web Server 2 for RHEL 5RedHatantlr-eap6-0:2.7.7-17.redhat_4.1.ep6.el5*
Red Hat JBoss Enterprise Web Server 2 for RHEL 5RedHatapache-commons-collections-eap6-0:3.2.1-15.redhat_3.1.ep6.el5*
Red Hat JBoss Enterprise Web Server 2 for RHEL 5RedHatapache-commons-daemon-eap6-1:1.0.15-5.redhat_1.ep6.el5*
Red Hat JBoss Enterprise Web Server 2 for RHEL 5RedHatapache-commons-daemon-jsvc-eap6-1:1.0.15-6.redhat_2.ep6.el5*
Red Hat JBoss Enterprise Web Server 2 for RHEL 5RedHatapache-commons-pool-eap6-0:1.6-7.redhat_6.1.ep6.el5*
Red Hat JBoss Enterprise Web Server 2 for RHEL 5RedHatdom4j-eap6-0:1.6.1-20.redhat_6.1.ep6.el5*
Red Hat JBoss Enterprise Web Server 2 for RHEL 5RedHatecj3-1:3.7.2-9.redhat_3.1.ep6.el5*
Red Hat JBoss Enterprise Web Server 2 for RHEL 5RedHathibernate4-eap6-0:4.2.14-3.SP1_redhat_1.1.ep6.el5*
Red Hat JBoss Enterprise Web Server 2 for RHEL 5RedHathttpd-0:2.2.26-35.ep6.el5*
Red Hat JBoss Enterprise Web Server 2 for RHEL 5RedHatjavassist-eap6-0:3.18.1-1.GA_redhat_1.1.ep6.el5*
Red Hat JBoss Enterprise Web Server 2 for RHEL 5RedHatjboss-logging-0:3.1.4-1.GA_redhat_1.1.ep6.el5*
Red Hat JBoss Enterprise Web Server 2 for RHEL 5RedHatjboss-transaction-api_1.1_spec-0:1.0.1-12.Final_redhat_2.2.ep6.el5*
Red Hat JBoss Enterprise Web Server 2 for RHEL 5RedHatmod_cluster-0:1.2.9-1.Final_redhat_1.1.ep6.el5*
Red Hat JBoss Enterprise Web Server 2 for RHEL 5RedHatmod_cluster-native-0:1.2.9-3.Final_redhat_2.ep6.el5*
Red Hat JBoss Enterprise Web Server 2 for RHEL 5RedHatmod_jk-0:1.2.40-2.redhat_1.ep6.el5*
Red Hat JBoss Enterprise Web Server 2 for RHEL 5RedHatmod_rt-0:2.4.1-6.GA.ep6.el5*
Red Hat JBoss Enterprise Web Server 2 for RHEL 5RedHatmod_snmp-0:2.4.1-13.GA.ep6.el5*
Red Hat JBoss Enterprise Web Server 2 for RHEL 5RedHatstoreconfig-tc6-0:0.0.1-7.Alpha3_redhat_12.3.ep6.el5*
Red Hat JBoss Enterprise Web Server 2 for RHEL 5RedHatstoreconfig-tc7-0:0.0.1-7.Alpha3_redhat_12.5.ep6.el5*
Red Hat JBoss Enterprise Web Server 2 for RHEL 5RedHattomcat6-0:6.0.41-6_patch_02.ep6.el5*
Red Hat JBoss Enterprise Web Server 2 for RHEL 5RedHattomcat7-0:7.0.54-6_patch_02.ep6.el5*
Red Hat JBoss Enterprise Web Server 2 for RHEL 5RedHattomcat-native-0:1.1.30-2.redhat_1.ep6.el5*
Red Hat JBoss Enterprise Web Server 2 for RHEL 6RedHatantlr-eap6-0:2.7.7-17.redhat_4.1.ep6.el6*
Red Hat JBoss Enterprise Web Server 2 for RHEL 6RedHatapache-commons-collections-eap6-0:3.2.1-15.redhat_3.1.ep6.el6*
Red Hat JBoss Enterprise Web Server 2 for RHEL 6RedHatapache-commons-daemon-eap6-1:1.0.15-5.redhat_1.ep6.el6*
Red Hat JBoss Enterprise Web Server 2 for RHEL 6RedHatapache-commons-daemon-jsvc-eap6-1:1.0.15-6.redhat_2.ep6.el6*
Red Hat JBoss Enterprise Web Server 2 for RHEL 6RedHatapache-commons-logging-eap6-0:1.1.1-7.9_redhat_1.ep6.el6*
Red Hat JBoss Enterprise Web Server 2 for RHEL 6RedHatapache-commons-pool-eap6-0:1.6-7.redhat_6.1.ep6.el6*
Red Hat JBoss Enterprise Web Server 2 for RHEL 6RedHatdom4j-eap6-0:1.6.1-20.redhat_6.1.ep6.el6*
Red Hat JBoss Enterprise Web Server 2 for RHEL 6RedHatecj3-1:3.7.2-9.redhat_3.1.ep6.el6*
Red Hat JBoss Enterprise Web Server 2 for RHEL 6RedHathibernate4-eap6-0:4.2.14-3.SP1_redhat_1.1.ep6.el6*
Red Hat JBoss Enterprise Web Server 2 for RHEL 6RedHathttpd-0:2.2.26-35.ep6.el6*
Red Hat JBoss Enterprise Web Server 2 for RHEL 6RedHatjavassist-eap6-0:3.18.1-1.GA_redhat_1.1.ep6.el6*
Red Hat JBoss Enterprise Web Server 2 for RHEL 6RedHatjboss-logging-0:3.1.4-1.GA_redhat_1.1.ep6.el6*
Red Hat JBoss Enterprise Web Server 2 for RHEL 6RedHatjboss-transaction-api_1.1_spec-0:1.0.1-12.Final_redhat_2.2.ep6.el6*
Red Hat JBoss Enterprise Web Server 2 for RHEL 6RedHatmod_cluster-0:1.2.9-1.Final_redhat_1.1.ep6.el6*
Red Hat JBoss Enterprise Web Server 2 for RHEL 6RedHatmod_cluster-native-0:1.2.9-3.Final_redhat_2.ep6.el6*
Red Hat JBoss Enterprise Web Server 2 for RHEL 6RedHatmod_jk-0:1.2.40-2.redhat_1.ep6.el6*
Red Hat JBoss Enterprise Web Server 2 for RHEL 6RedHatmod_rt-0:2.4.1-6.GA.ep6.el6*
Red Hat JBoss Enterprise Web Server 2 for RHEL 6RedHatmod_snmp-0:2.4.1-13.GA.ep6.el6*
Red Hat JBoss Enterprise Web Server 2 for RHEL 6RedHatstoreconfig-tc6-0:0.0.1-7.Alpha3_redhat_12.3.ep6.el6*
Red Hat JBoss Enterprise Web Server 2 for RHEL 6RedHatstoreconfig-tc7-0:0.0.1-7.Alpha3_redhat_12.5.ep6.el6*
Red Hat JBoss Enterprise Web Server 2 for RHEL 6RedHattomcat6-0:6.0.41-5_patch_02.ep6.el6*
Red Hat JBoss Enterprise Web Server 2 for RHEL 6RedHattomcat7-0:7.0.54-6_patch_02.ep6.el6*
Red Hat JBoss Enterprise Web Server 2 for RHEL 6RedHattomcat-native-0:1.1.30-2.redhat_1.ep6.el6*
Red Hat JBoss Fuse Service Works 6.0RedHatjbossweb*
Red Hat JBoss Portal 6.2RedHatjbossweb*
Red Hat JBoss Web Server 2.1RedHattomcat6*
Red Hat JBoss Web Server 2.1RedHattomcat7*
Tomcat6Ubuntuesm-infra-legacy/trusty*
Tomcat6Ubuntulucid*
Tomcat6Ubuntuprecise*
Tomcat6Ubuntuprecise/esm*
Tomcat6Ubuntusaucy*
Tomcat6Ubuntutrusty*
Tomcat6Ubuntutrusty/esm*
Tomcat6Ubuntuupstream*
Tomcat7Ubuntuesm-infra-legacy/trusty*
Tomcat7Ubuntuprecise*
Tomcat7Ubuntusaucy*
Tomcat7Ubuntutrusty*
Tomcat7Ubuntutrusty/esm*
Tomcat7Ubuntuupstream*
Tomcat8Ubuntuupstream*

References