PT-2014-1444 · Apache+5 · Apache Tomcat+5

Publicado

2014-03-27

·

Atualizado

2022-05-14

·

CVE-2014-0096

CVSS v2.0

4.3

Média

VetorAV:N/AC:M/Au:N/C:P/I:N/A:N
Name of the Vulnerable Software and Affected Versions Apache Tomcat versions prior to 6.0.40 Apache Tomcat versions 7.x prior to 7.0.53 Apache Tomcat versions 8.x prior to 8.0.4
Description The issue exists due to improper restriction of XSLT stylesheets in the default servlet of Apache Tomcat, allowing remote attackers to bypass security restrictions and read arbitrary files. This is related to an XML External Entity (XXE) issue, where a crafted web application can provide an XML external entity declaration in conjunction with an entity reference. The problem enables a malicious web application to bypass file access constraints imposed by the security manager via the use of external XML entities.
Recommendations For Apache Tomcat versions prior to 6.0.40, update to version 6.0.40 or later. For Apache Tomcat versions 7.x prior to 7.0.53, update to version 7.0.53 or later. For Apache Tomcat versions 8.x prior to 8.0.4, update to version 8.0.4 or later. As a temporary workaround, consider disabling the use of XSLT stylesheets in the default servlet until a patch is available. Restrict access to the default servlet to minimize the risk of exploitation.

Correção

RCE

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

BDU:2015-00406
CESA-2014_0865
CVE-2014-0096
DSA-3530-1
DSA-3552-1
GHSA-QPRX-Q2R7-3RX6
HPSBUX03102
MGASA-2014-0268
RHSA-2014:0827
RHSA-2014:0834
RHSA-2014:0835
RHSA-2014:0843
RHSA-2014:0865
RHSA-2014_0827
RHSA-2014_0865
USN-2302-1

Produtos afetados

Apache Tomcat
Centos
Hp-Ux
Red Hat
Suse
Ubuntu