CVE Vulnerabilities

CVE-2014-0119

Published: May 31, 2014 | Modified: Nov 07, 2023
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
4.3 MEDIUM
AV:N/AC:M/Au:N/C:P/I:N/A:N
RedHat/V2
2.1 LOW
AV:N/AC:H/Au:S/C:P/I:N/A:N
RedHat/V3
Ubuntu
LOW

Apache Tomcat before 6.0.40, 7.x before 7.0.54, and 8.x before 8.0.6 does not properly constrain the class loader that accesses the XML parser used with an XSLT stylesheet, which allows remote attackers to (1) read arbitrary files via a crafted web application that provides an XML external entity declaration in conjunction with an entity reference, related to an XML External Entity (XXE) issue, or (2) read files associated with different web applications on a single Tomcat instance via a crafted web application.

Affected Software

Name Vendor Start Version End Version
Tomcat Apache 8.0.0-rc1 (including) 8.0.0-rc1 (including)
Tomcat Apache 8.0.0-rc10 (including) 8.0.0-rc10 (including)
Tomcat Apache 8.0.0-rc2 (including) 8.0.0-rc2 (including)
Tomcat Apache 8.0.0-rc5 (including) 8.0.0-rc5 (including)
Tomcat Apache 8.0.1 (including) 8.0.1 (including)
Tomcat Apache 8.0.3 (including) 8.0.3 (including)
Tomcat Apache 8.0.5 (including) 8.0.5 (including)
Red Hat Enterprise Linux 6 RedHat tomcat6-0:6.0.24-78.el6_5 *
Red Hat Enterprise Linux 7 RedHat tomcat-0:7.0.42-8.el7_0 *
Red Hat JBoss BPMS 6.0 RedHat jbossweb *
Red Hat JBoss BRMS 6.0 RedHat jbossweb *
Red Hat JBoss Data Grid 6.3 RedHat jbossweb *
Red Hat JBoss Data Virtualization 6.0 RedHat jbossweb *
Red Hat JBoss Data Virtualization 6.1 RedHat *
Red Hat JBoss Enterprise Application Platform 6.2 RedHat jbossweb *
Red Hat JBoss Enterprise Application Platform 6.2 for RHEL 5 RedHat jbossweb-0:7.3.2-4.Final_redhat_3.1.ep6.el5 *
Red Hat JBoss Enterprise Application Platform 6.2 for RHEL 6 RedHat jbossweb-0:7.3.2-4.Final_redhat_3.1.ep6.el6 *
Red Hat JBoss Enterprise Web Server 2 for RHEL 5 RedHat antlr-eap6-0:2.7.7-17.redhat_4.1.ep6.el5 *
Red Hat JBoss Enterprise Web Server 2 for RHEL 5 RedHat apache-commons-collections-eap6-0:3.2.1-15.redhat_3.1.ep6.el5 *
Red Hat JBoss Enterprise Web Server 2 for RHEL 5 RedHat apache-commons-daemon-eap6-1:1.0.15-5.redhat_1.ep6.el5 *
Red Hat JBoss Enterprise Web Server 2 for RHEL 5 RedHat apache-commons-daemon-jsvc-eap6-1:1.0.15-6.redhat_2.ep6.el5 *
Red Hat JBoss Enterprise Web Server 2 for RHEL 5 RedHat apache-commons-pool-eap6-0:1.6-7.redhat_6.1.ep6.el5 *
Red Hat JBoss Enterprise Web Server 2 for RHEL 5 RedHat dom4j-eap6-0:1.6.1-20.redhat_6.1.ep6.el5 *
Red Hat JBoss Enterprise Web Server 2 for RHEL 5 RedHat ecj3-1:3.7.2-9.redhat_3.1.ep6.el5 *
Red Hat JBoss Enterprise Web Server 2 for RHEL 5 RedHat hibernate4-eap6-0:4.2.14-3.SP1_redhat_1.1.ep6.el5 *
Red Hat JBoss Enterprise Web Server 2 for RHEL 5 RedHat httpd-0:2.2.26-35.ep6.el5 *
Red Hat JBoss Enterprise Web Server 2 for RHEL 5 RedHat javassist-eap6-0:3.18.1-1.GA_redhat_1.1.ep6.el5 *
Red Hat JBoss Enterprise Web Server 2 for RHEL 5 RedHat jboss-logging-0:3.1.4-1.GA_redhat_1.1.ep6.el5 *
Red Hat JBoss Enterprise Web Server 2 for RHEL 5 RedHat jboss-transaction-api_1.1_spec-0:1.0.1-12.Final_redhat_2.2.ep6.el5 *
Red Hat JBoss Enterprise Web Server 2 for RHEL 5 RedHat mod_cluster-0:1.2.9-1.Final_redhat_1.1.ep6.el5 *
Red Hat JBoss Enterprise Web Server 2 for RHEL 5 RedHat mod_cluster-native-0:1.2.9-3.Final_redhat_2.ep6.el5 *
Red Hat JBoss Enterprise Web Server 2 for RHEL 5 RedHat mod_jk-0:1.2.40-2.redhat_1.ep6.el5 *
Red Hat JBoss Enterprise Web Server 2 for RHEL 5 RedHat mod_rt-0:2.4.1-6.GA.ep6.el5 *
Red Hat JBoss Enterprise Web Server 2 for RHEL 5 RedHat mod_snmp-0:2.4.1-13.GA.ep6.el5 *
Red Hat JBoss Enterprise Web Server 2 for RHEL 5 RedHat storeconfig-tc6-0:0.0.1-7.Alpha3_redhat_12.3.ep6.el5 *
Red Hat JBoss Enterprise Web Server 2 for RHEL 5 RedHat storeconfig-tc7-0:0.0.1-7.Alpha3_redhat_12.5.ep6.el5 *
Red Hat JBoss Enterprise Web Server 2 for RHEL 5 RedHat tomcat6-0:6.0.41-6_patch_02.ep6.el5 *
Red Hat JBoss Enterprise Web Server 2 for RHEL 5 RedHat tomcat7-0:7.0.54-6_patch_02.ep6.el5 *
Red Hat JBoss Enterprise Web Server 2 for RHEL 5 RedHat tomcat-native-0:1.1.30-2.redhat_1.ep6.el5 *
Red Hat JBoss Enterprise Web Server 2 for RHEL 6 RedHat antlr-eap6-0:2.7.7-17.redhat_4.1.ep6.el6 *
Red Hat JBoss Enterprise Web Server 2 for RHEL 6 RedHat apache-commons-collections-eap6-0:3.2.1-15.redhat_3.1.ep6.el6 *
Red Hat JBoss Enterprise Web Server 2 for RHEL 6 RedHat apache-commons-daemon-eap6-1:1.0.15-5.redhat_1.ep6.el6 *
Red Hat JBoss Enterprise Web Server 2 for RHEL 6 RedHat apache-commons-daemon-jsvc-eap6-1:1.0.15-6.redhat_2.ep6.el6 *
Red Hat JBoss Enterprise Web Server 2 for RHEL 6 RedHat apache-commons-logging-eap6-0:1.1.1-7.9_redhat_1.ep6.el6 *
Red Hat JBoss Enterprise Web Server 2 for RHEL 6 RedHat apache-commons-pool-eap6-0:1.6-7.redhat_6.1.ep6.el6 *
Red Hat JBoss Enterprise Web Server 2 for RHEL 6 RedHat dom4j-eap6-0:1.6.1-20.redhat_6.1.ep6.el6 *
Red Hat JBoss Enterprise Web Server 2 for RHEL 6 RedHat ecj3-1:3.7.2-9.redhat_3.1.ep6.el6 *
Red Hat JBoss Enterprise Web Server 2 for RHEL 6 RedHat hibernate4-eap6-0:4.2.14-3.SP1_redhat_1.1.ep6.el6 *
Red Hat JBoss Enterprise Web Server 2 for RHEL 6 RedHat httpd-0:2.2.26-35.ep6.el6 *
Red Hat JBoss Enterprise Web Server 2 for RHEL 6 RedHat javassist-eap6-0:3.18.1-1.GA_redhat_1.1.ep6.el6 *
Red Hat JBoss Enterprise Web Server 2 for RHEL 6 RedHat jboss-logging-0:3.1.4-1.GA_redhat_1.1.ep6.el6 *
Red Hat JBoss Enterprise Web Server 2 for RHEL 6 RedHat jboss-transaction-api_1.1_spec-0:1.0.1-12.Final_redhat_2.2.ep6.el6 *
Red Hat JBoss Enterprise Web Server 2 for RHEL 6 RedHat mod_cluster-0:1.2.9-1.Final_redhat_1.1.ep6.el6 *
Red Hat JBoss Enterprise Web Server 2 for RHEL 6 RedHat mod_cluster-native-0:1.2.9-3.Final_redhat_2.ep6.el6 *
Red Hat JBoss Enterprise Web Server 2 for RHEL 6 RedHat mod_jk-0:1.2.40-2.redhat_1.ep6.el6 *
Red Hat JBoss Enterprise Web Server 2 for RHEL 6 RedHat mod_rt-0:2.4.1-6.GA.ep6.el6 *
Red Hat JBoss Enterprise Web Server 2 for RHEL 6 RedHat mod_snmp-0:2.4.1-13.GA.ep6.el6 *
Red Hat JBoss Enterprise Web Server 2 for RHEL 6 RedHat storeconfig-tc6-0:0.0.1-7.Alpha3_redhat_12.3.ep6.el6 *
Red Hat JBoss Enterprise Web Server 2 for RHEL 6 RedHat storeconfig-tc7-0:0.0.1-7.Alpha3_redhat_12.5.ep6.el6 *
Red Hat JBoss Enterprise Web Server 2 for RHEL 6 RedHat tomcat6-0:6.0.41-5_patch_02.ep6.el6 *
Red Hat JBoss Enterprise Web Server 2 for RHEL 6 RedHat tomcat7-0:7.0.54-6_patch_02.ep6.el6 *
Red Hat JBoss Enterprise Web Server 2 for RHEL 6 RedHat tomcat-native-0:1.1.30-2.redhat_1.ep6.el6 *
Red Hat JBoss Fuse Service Works 6.0 RedHat jbossweb *
Red Hat JBoss Portal 6.2 RedHat jbossweb *
Red Hat JBoss Web Server 2.1 RedHat tomcat6 *
Red Hat JBoss Web Server 2.1 RedHat tomcat7 *
Tomcat6 Ubuntu lucid *
Tomcat6 Ubuntu precise *
Tomcat6 Ubuntu precise/esm *
Tomcat6 Ubuntu saucy *
Tomcat6 Ubuntu trusty *
Tomcat6 Ubuntu upstream *
Tomcat7 Ubuntu precise *
Tomcat7 Ubuntu saucy *
Tomcat7 Ubuntu trusty *
Tomcat7 Ubuntu upstream *
Tomcat8 Ubuntu upstream *

References