PT-2014-1444 · Apache+5 · Apache Tomcat+5

Published

2014-03-27

·

Updated

2022-05-14

·

CVE-2014-0096

CVSS v2.0

4.3

Medium

VectorAV:N/AC:M/Au:N/C:P/I:N/A:N
Name of the Vulnerable Software and Affected Versions Apache Tomcat versions prior to 6.0.40 Apache Tomcat versions 7.x prior to 7.0.53 Apache Tomcat versions 8.x prior to 8.0.4
Description The issue exists due to improper restriction of XSLT stylesheets in the default servlet of Apache Tomcat, allowing remote attackers to bypass security restrictions and read arbitrary files. This is related to an XML External Entity (XXE) issue, where a crafted web application can provide an XML external entity declaration in conjunction with an entity reference. The problem enables a malicious web application to bypass file access constraints imposed by the security manager via the use of external XML entities.
Recommendations For Apache Tomcat versions prior to 6.0.40, update to version 6.0.40 or later. For Apache Tomcat versions 7.x prior to 7.0.53, update to version 7.0.53 or later. For Apache Tomcat versions 8.x prior to 8.0.4, update to version 8.0.4 or later. As a temporary workaround, consider disabling the use of XSLT stylesheets in the default servlet until a patch is available. Restrict access to the default servlet to minimize the risk of exploitation.

Fix

RCE

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2015-00406
CESA-2014_0865
CVE-2014-0096
DSA-3530-1
DSA-3552-1
GHSA-QPRX-Q2R7-3RX6
HPSBUX03102
MGASA-2014-0268
RHSA-2014:0827
RHSA-2014:0834
RHSA-2014:0835
RHSA-2014:0843
RHSA-2014:0865
RHSA-2014_0827
RHSA-2014_0865
USN-2302-1

Affected Products

Apache Tomcat
Centos
Hp-Ux
Red Hat
Suse
Ubuntu