TROYANOSYVIRUS
Zuruck zu CVEs

CVE-2014-0107

N/A

Beschreibung

The TransformerFactory in Apache Xalan-Java before 2.7.2 does not properly restrict access to certain properties when FEATURE_SECURE_PROCESSING is enabled, which allows remote attackers to bypass expected restrictions and load arbitrary classes or access external resources via a crafted (1) xalan:content-header, (2) xalan:entities, (3) xslt:content-header, or (4) xslt:entities property, or a Java property that is bound to the XSLT 1.0 system-property function.

CVE Details

CVSS v3.1 BewertungN/A
Veroffentlicht4/15/2014
Zuletzt geandert4/12/2025
Quellenvd
Honeypot-Sichtungen0

Betroffene Produkte

apache:xalan-javaoracle:webcenter_sites

Schwachen (CWE)

CWE-264

Referenzen

http://rhn.redhat.com/errata/RHSA-2014-0348.html(af854a3a-2127-422b-91ae-364da2661108)
http://rhn.redhat.com/errata/RHSA-2014-1351.html(af854a3a-2127-422b-91ae-364da2661108)
http://rhn.redhat.com/errata/RHSA-2015-1888.html(af854a3a-2127-422b-91ae-364da2661108)
http://secunia.com/advisories/57563(af854a3a-2127-422b-91ae-364da2661108)
http://secunia.com/advisories/59036(af854a3a-2127-422b-91ae-364da2661108)
http://secunia.com/advisories/59151(af854a3a-2127-422b-91ae-364da2661108)
http://secunia.com/advisories/59247(af854a3a-2127-422b-91ae-364da2661108)
http://secunia.com/advisories/59290(af854a3a-2127-422b-91ae-364da2661108)
http://secunia.com/advisories/59291(af854a3a-2127-422b-91ae-364da2661108)
http://secunia.com/advisories/59369(af854a3a-2127-422b-91ae-364da2661108)
http://secunia.com/advisories/59515(af854a3a-2127-422b-91ae-364da2661108)
http://secunia.com/advisories/59711(af854a3a-2127-422b-91ae-364da2661108)
http://secunia.com/advisories/60502(af854a3a-2127-422b-91ae-364da2661108)
http://www-01.ibm.com/support/docview.wss?uid=swg21674334(af854a3a-2127-422b-91ae-364da2661108)
http://www-01.ibm.com/support/docview.wss?uid=swg21676093(af854a3a-2127-422b-91ae-364da2661108)
http://www-01.ibm.com/support/docview.wss?uid=swg21677145(af854a3a-2127-422b-91ae-364da2661108)
http://www-01.ibm.com/support/docview.wss?uid=swg21680703(af854a3a-2127-422b-91ae-364da2661108)
http://www-01.ibm.com/support/docview.wss?uid=swg21681933(af854a3a-2127-422b-91ae-364da2661108)
http://www.debian.org/security/2014/dsa-2886(af854a3a-2127-422b-91ae-364da2661108)
http://www.ibm.com/support/docview.wss?uid=swg21677967(af854a3a-2127-422b-91ae-364da2661108)
http://www.ocert.org/advisories/ocert-2014-002.html(af854a3a-2127-422b-91ae-364da2661108)
http://www.securityfocus.com/bid/66397(af854a3a-2127-422b-91ae-364da2661108)
http://www.securitytracker.com/id/1034711(af854a3a-2127-422b-91ae-364da2661108)
http://www.securitytracker.com/id/1034716(af854a3a-2127-422b-91ae-364da2661108)
https://issues.apache.org/jira/browse/XALANJ-2435(af854a3a-2127-422b-91ae-364da2661108)
https://security.gentoo.org/glsa/201604-02(af854a3a-2127-422b-91ae-364da2661108)
https://www.oracle.com//security-alerts/cpujul2021.html(af854a3a-2127-422b-91ae-364da2661108)
https://www.oracle.com/security-alerts/cpuoct2021.html(af854a3a-2127-422b-91ae-364da2661108)
https://www.tenable.com/security/tns-2018-15(af854a3a-2127-422b-91ae-364da2661108)

IOC Korrelationen

Keine Korrelationen erfasst

This product uses data from the NVD API but is not endorsed or certified by the NVD.