CVE-2014-0107

Severity

75%

Complexity

99%

Confidentiality

106%

The TransformerFactory in Apache Xalan-Java before 2.7.2 does not properly restrict access to certain properties when FEATURE_SECURE_PROCESSING is enabled, which allows remote attackers to bypass expected restrictions and load arbitrary classes or access external resources via a crafted (1) xalan:content-header, (2) xalan:entities, (3) xslt:content-header, or (4) xslt:entities property, or a Java property that is bound to the XSLT 1.0 system-property function.

The TransformerFactory in Apache Xalan-Java before 2.7.2 does not properly restrict access to certain properties when FEATURE_SECURE_PROCESSING is enabled, which allows remote attackers to bypass expected restrictions and load arbitrary classes or access external resources via a crafted (1) xalan:content-header, (2) xalan:entities, (3) xslt:content-header, or (4) xslt:entities property, or a Java property that is bound to the XSLT 1.0 system-property function.

CVSS 2.0 Base Score 7.5. CVSS Attack Vector: network. CVSS Attack Complexity: low. CVSS Vector: (AV:N/AC:L/Au:N/C:P/I:P/A:P).

Overview

First reported 10 years ago

2014-04-15 23:13:00

Last updated 5 years ago

2019-04-23 19:29:00

Affected Software

Apache Software Foundation Xalan-Java 1.0.0

1.0.0

Apache Software Foundation Xalan-Java 2.0.0

2.0.0

Apache Software Foundation Xalan-Java 2.0.1

2.0.1

Apache Software Foundation Xalan-Java 2.1.0

2.1.0

Apache Software Foundation Xalan-Java 2.2.0

2.2.0

Apache Software Foundation Xalan-Java 2.4.0

2.4.0

Apache Software Foundation Xalan-Java 2.4.1

2.4.1

Apache Software Foundation Xalan-Java 2.5.0

2.5.0

Apache Software Foundation Xalan-Java 2.5.1

2.5.1

Apache Software Foundation Xalan-Java 2.5.2

2.5.2

Apache Software Foundation Xalan-Java 2.6.0

2.6.0

Apache Software Foundation Xalan-Java 2.7.0

2.7.0

Oracle Webcenter Sites 7.6.2

7.6.2

Oracle Webcenter Sites 11.1.1.8.0

11.1.1.8.0

Stay updated

ExploitPedia is constantly evolving. Sign up to receive a notification when we release additional functionality.

Get in touch

If you'd like to report a bug or have any suggestions for improvements then please do get in touch with us using this form. We will get back to you as soon as we can.