National Vulnerability Database

National Vulnerability Database

National Vulnerability
Database

CVE-2014-0119 Detail

Current Description

Apache Tomcat before 6.0.40, 7.x before 7.0.54, and 8.x before 8.0.6 does not properly constrain the class loader that accesses the XML parser used with an XSLT stylesheet, which allows remote attackers to (1) read arbitrary files via a crafted web application that provides an XML external entity declaration in conjunction with an entity reference, related to an XML External Entity (XXE) issue, or (2) read files associated with different web applications on a single Tomcat instance via a crafted web application.

Source:  MITRE
View Analysis Description

Severity



CVSS 3.x Severity and Metrics:

NIST CVSS score
NIST: NVD
Base Score: N/A
NVD score not yet provided.

References to Advisories, Solutions, and Tools

By selecting these links, you will be leaving NIST webspace. We have provided these links to other web sites because they may have information that would be of interest to you. No inferences should be drawn on account of other sites being referenced, or not, from this page. There may be other web sites that are more appropriate for your purpose. NIST does not necessarily endorse the views expressed, or concur with the facts presented on these sites. Further, NIST does not endorse any commercial products that may be mentioned on these sites. Please address comments about this page to nvd@nist.gov.

Hyperlink Resource
http://advisories.mageia.org/MGASA-2014-0268.html
http://marc.info/?l=bugtraq&m=141017844705317&w=2
http://marc.info/?l=bugtraq&m=144498216801440&w=2
http://rhn.redhat.com/errata/RHSA-2015-0675.html
http://rhn.redhat.com/errata/RHSA-2015-0720.html
http://rhn.redhat.com/errata/RHSA-2015-0765.html
http://seclists.org/fulldisclosure/2014/Dec/23
http://seclists.org/fulldisclosure/2014/May/141
http://svn.apache.org/viewvc?view=revision&revision=1588193
http://svn.apache.org/viewvc?view=revision&revision=1588199
http://svn.apache.org/viewvc?view=revision&revision=1589640
http://svn.apache.org/viewvc?view=revision&revision=1589837
http://svn.apache.org/viewvc?view=revision&revision=1589980
http://svn.apache.org/viewvc?view=revision&revision=1589983
http://svn.apache.org/viewvc?view=revision&revision=1589985
http://svn.apache.org/viewvc?view=revision&revision=1589990
http://svn.apache.org/viewvc?view=revision&revision=1589992
http://svn.apache.org/viewvc?view=revision&revision=1589997
http://svn.apache.org/viewvc?view=revision&revision=1590028
http://svn.apache.org/viewvc?view=revision&revision=1590036
http://svn.apache.org/viewvc?view=revision&revision=1593815
http://svn.apache.org/viewvc?view=revision&revision=1593821
http://tomcat.apache.org/security-6.html Vendor Advisory
http://tomcat.apache.org/security-7.html Vendor Advisory
http://tomcat.apache.org/security-8.html Vendor Advisory
http://www.debian.org/security/2016/dsa-3530
http://www.debian.org/security/2016/dsa-3552
http://www.mandriva.com/security/advisories?name=MDVSA-2015:052
http://www.mandriva.com/security/advisories?name=MDVSA-2015:053
http://www.mandriva.com/security/advisories?name=MDVSA-2015:084
http://www.oracle.com/technetwork/security-advisory/cpuoct2016-2881722.html
http://www.oracle.com/technetwork/topics/security/cpujul2014-1972956.html
http://www.oracle.com/technetwork/topics/security/cpuoct2014-1972960.html
http://www.securityfocus.com/archive/1/534161/100/0/threaded
http://www.securityfocus.com/bid/67669
http://www.securitytracker.com/id/1030298
http://www.ubuntu.com/usn/USN-2654-1
http://www.vmware.com/security/advisories/VMSA-2014-0012.html
http://www-01.ibm.com/support/docview.wss?uid=swg21678231
http://www-01.ibm.com/support/docview.wss?uid=swg21681528
https://h20564.www2.hpe.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c04851013
https://lists.apache.org/thread.html/37220405a377c0182d2afdbc36461c4783b2930fbeae3a17f1333113@%3Cdev.tomcat.apache.org%3E
https://lists.apache.org/thread.html/39ae1f0bd5867c15755a6f959b271ade1aea04ccdc3b2e639dcd903b@%3Cdev.tomcat.apache.org%3E
https://lists.apache.org/thread.html/b84ad1258a89de5c9c853c7f2d3ad77e5b8b2930be9e132d5cef6b95@%3Cdev.tomcat.apache.org%3E
https://lists.apache.org/thread.html/b8a1bf18155b552dcf9a928ba808cbadad84c236d85eab3033662cfb@%3Cdev.tomcat.apache.org%3E

Weakness Enumeration

CWE-ID CWE Name Source
CWE-264 Permissions, Privileges, and Access Controls NIST  

Known Affected Software Configurations Switch to CPE 2.2

Configuration 1 ( hide )
 cpe:2.3:a:apache:tomcat:8.0.0:rc1:*:*:*:*:*:*
     Show Matching CPE(s)
 cpe:2.3:a:apache:tomcat:8.0.0:rc10:*:*:*:*:*:*
     Show Matching CPE(s)
 cpe:2.3:a:apache:tomcat:8.0.0:rc2:*:*:*:*:*:*
     Show Matching CPE(s)
 cpe:2.3:a:apache:tomcat:8.0.0:rc5:*:*:*:*:*:*
     Show Matching CPE(s)
 cpe:2.3:a:apache:tomcat:8.0.1:*:*:*:*:*:*:*
     Show Matching CPE(s)
 cpe:2.3:a:apache:tomcat:8.0.3:*:*:*:*:*:*:*
     Show Matching CPE(s)
 cpe:2.3:a:apache:tomcat:8.0.5:*:*:*:*:*:*:*
     Show Matching CPE(s)

Configuration 2 ( hide )
 cpe:2.3:a:apache:tomcat:6:*:*:*:*:*:*:*
     Show Matching CPE(s)
 cpe:2.3:a:apache:tomcat:6.0:*:*:*:*:*:*:*
     Show Matching CPE(s)
 cpe:2.3:a:apache:tomcat:6.0.0:*:*:*:*:*:*:*
     Show Matching CPE(s)
 cpe:2.3:a:apache:tomcat:6.0.0:alpha:*:*:*:*:*:*
     Show Matching CPE(s)
 cpe:2.3:a:apache:tomcat:6.0.1:*:*:*:*:*:*:*
     Show Matching CPE(s)
 cpe:2.3:a:apache:tomcat:6.0.1:alpha:*:*:*:*:*:*
     Show Matching CPE(s)
 cpe:2.3:a:apache:tomcat:6.0.2:*:*:*:*:*:*:*
     Show Matching CPE(s)
 cpe:2.3:a:apache:tomcat:6.0.2:alpha:*:*:*:*:*:*
     Show Matching CPE(s)
 cpe:2.3:a:apache:tomcat:6.0.2:beta:*:*:*:*:*:*
     Show Matching CPE(s)
 cpe:2.3:a:apache:tomcat:6.0.3:*:*:*:*:*:*:*
     Show Matching CPE(s)
 cpe:2.3:a:apache:tomcat:6.0.4:*:*:*:*:*:*:*
     Show Matching CPE(s)
 cpe:2.3:a:apache:tomcat:6.0.4:alpha:*:*:*:*:*:*
     Show Matching CPE(s)
 cpe:2.3:a:apache:tomcat:6.0.5:*:*:*:*:*:*:*
     Show Matching CPE(s)
 cpe:2.3:a:apache:tomcat:6.0.6:*:*:*:*:*:*:*
     Show Matching CPE(s)
 cpe:2.3:a:apache:tomcat:6.0.6:alpha:*:*:*:*:*:*
     Show Matching CPE(s)
 cpe:2.3:a:apache:tomcat:6.0.7:*:*:*:*:*:*:*
     Show Matching CPE(s)
 cpe:2.3:a:apache:tomcat:6.0.7:alpha:*:*:*:*:*:*
     Show Matching CPE(s)
 cpe:2.3:a:apache:tomcat:6.0.7:beta:*:*:*:*:*:*
     Show Matching CPE(s)
 cpe:2.3:a:apache:tomcat:6.0.8:*:*:*:*:*:*:*
     Show Matching CPE(s)
 cpe:2.3:a:apache:tomcat:6.0.8:alpha:*:*:*:*:*:*
     Show Matching CPE(s)
 cpe:2.3:a:apache:tomcat:6.0.9:*:*:*:*:*:*:*
     Show Matching CPE(s)
 cpe:2.3:a:apache:tomcat:6.0.9:beta:*:*:*:*:*:*
     Show Matching CPE(s)
 cpe:2.3:a:apache:tomcat:6.0.10:*:*:*:*:*:*:*
     Show Matching CPE(s)
 cpe:2.3:a:apache:tomcat:6.0.11:*:*:*:*:*:*:*
     Show Matching CPE(s)
 cpe:2.3:a:apache:tomcat:6.0.12:*:*:*:*:*:*:*
     Show Matching CPE(s)
 cpe:2.3:a:apache:tomcat:6.0.13:*:*:*:*:*:*:*
     Show Matching CPE(s)
 cpe:2.3:a:apache:tomcat:6.0.14:*:*:*:*:*:*:*
     Show Matching CPE(s)
 cpe:2.3:a:apache:tomcat:6.0.15:*:*:*:*:*:*:*
     Show Matching CPE(s)
 cpe:2.3:a:apache:tomcat:6.0.16:*:*:*:*:*:*:*
     Show Matching CPE(s)
 cpe:2.3:a:apache:tomcat:6.0.17:*:*:*:*:*:*:*
     Show Matching CPE(s)
 cpe:2.3:a:apache:tomcat:6.0.18:*:*:*:*:*:*:*
     Show Matching CPE(s)
 cpe:2.3:a:apache:tomcat:6.0.19:*:*:*:*:*:*:*
     Show Matching CPE(s)
 cpe:2.3:a:apache:tomcat:6.0.20:*:*:*:*:*:*:*
     Show Matching CPE(s)
 cpe:2.3:a:apache:tomcat:6.0.24:*:*:*:*:*:*:*
     Show Matching CPE(s)
 cpe:2.3:a:apache:tomcat:6.0.26:*:*:*:*:*:*:*
     Show Matching CPE(s)
 cpe:2.3:a:apache:tomcat:6.0.27:*:*:*:*:*:*:*
     Show Matching CPE(s)
 cpe:2.3:a:apache:tomcat:6.0.28:*:*:*:*:*:*:*
     Show Matching CPE(s)
 cpe:2.3:a:apache:tomcat:6.0.29:*:*:*:*:*:*:*
     Show Matching CPE(s)
 cpe:2.3:a:apache:tomcat:6.0.30:*:*:*:*:*:*:*
     Show Matching CPE(s)
 cpe:2.3:a:apache:tomcat:6.0.31:*:*:*:*:*:*:*
     Show Matching CPE(s)
 cpe:2.3:a:apache:tomcat:6.0.32:*:*:*:*:*:*:*
     Show Matching CPE(s)
 cpe:2.3:a:apache:tomcat:6.0.33:*:*:*:*:*:*:*
     Show Matching CPE(s)
 cpe:2.3:a:apache:tomcat:6.0.35:*:*:*:*:*:*:*
     Show Matching CPE(s)
 cpe:2.3:a:apache:tomcat:6.0.36:*:*:*:*:*:*:*
     Show Matching CPE(s)
 cpe:2.3:a:apache:tomcat:6.0.37:*:*:*:*:*:*:*
     Show Matching CPE(s)
 cpe:2.3:a:apache:tomcat:*:*:*:*:*:*:*:*
     Show Matching CPE(s)
Up to (including)
6.0.39

Configuration 3 ( hide )
 cpe:2.3:a:apache:tomcat:7.0.0:*:*:*:*:*:*:*
     Show Matching CPE(s)
 cpe:2.3:a:apache:tomcat:7.0.0:beta:*:*:*:*:*:*
     Show Matching CPE(s)
 cpe:2.3:a:apache:tomcat:7.0.1:*:*:*:*:*:*:*
     Show Matching CPE(s)
 cpe:2.3:a:apache:tomcat:7.0.2:*:*:*:*:*:*:*
     Show Matching CPE(s)
 cpe:2.3:a:apache:tomcat:7.0.2:beta:*:*:*:*:*:*
     Show Matching CPE(s)
 cpe:2.3:a:apache:tomcat:7.0.3:*:*:*:*:*:*:*
     Show Matching CPE(s)
 cpe:2.3:a:apache:tomcat:7.0.4:*:*:*:*:*:*:*
     Show Matching CPE(s)
 cpe:2.3:a:apache:tomcat:7.0.4:beta:*:*:*:*:*:*
     Show Matching CPE(s)
 cpe:2.3:a:apache:tomcat:7.0.5:*:*:*:*:*:*:*
     Show Matching CPE(s)
 cpe:2.3:a:apache:tomcat:7.0.6:*:*:*:*:*:*:*
     Show Matching CPE(s)
 cpe:2.3:a:apache:tomcat:7.0.7:*:*:*:*:*:*:*
     Show Matching CPE(s)
 cpe:2.3:a:apache:tomcat:7.0.8:*:*:*:*:*:*:*
     Show Matching CPE(s)
 cpe:2.3:a:apache:tomcat:7.0.9:*:*:*:*:*:*:*
     Show Matching CPE(s)
 cpe:2.3:a:apache:tomcat:7.0.10:*:*:*:*:*:*:*
     Show Matching CPE(s)
 cpe:2.3:a:apache:tomcat:7.0.11:*:*:*:*:*:*:*
     Show Matching CPE(s)
 cpe:2.3:a:apache:tomcat:7.0.12:*:*:*:*:*:*:*
     Show Matching CPE(s)
 cpe:2.3:a:apache:tomcat:7.0.13:*:*:*:*:*:*:*
     Show Matching CPE(s)
 cpe:2.3:a:apache:tomcat:7.0.14:*:*:*:*:*:*:*
     Show Matching CPE(s)
 cpe:2.3:a:apache:tomcat:7.0.15:*:*:*:*:*:*:*
     Show Matching CPE(s)
 cpe:2.3:a:apache:tomcat:7.0.16:*:*:*:*:*:*:*
     Show Matching CPE(s)
 cpe:2.3:a:apache:tomcat:7.0.17:*:*:*:*:*:*:*
     Show Matching CPE(s)
 cpe:2.3:a:apache:tomcat:7.0.18:*:*:*:*:*:*:*
     Show Matching CPE(s)
 cpe:2.3:a:apache:tomcat:7.0.19:*:*:*:*:*:*:*
     Show Matching CPE(s)
 cpe:2.3:a:apache:tomcat:7.0.20:*:*:*:*:*:*:*
     Show Matching CPE(s)
 cpe:2.3:a:apache:tomcat:7.0.21:*:*:*:*:*:*:*
     Show Matching CPE(s)
 cpe:2.3:a:apache:tomcat:7.0.22:*:*:*:*:*:*:*
     Show Matching CPE(s)
 cpe:2.3:a:apache:tomcat:7.0.23:*:*:*:*:*:*:*
     Show Matching CPE(s)
 cpe:2.3:a:apache:tomcat:7.0.24:*:*:*:*:*:*:*
     Show Matching CPE(s)
 cpe:2.3:a:apache:tomcat:7.0.25:*:*:*:*:*:*:*
     Show Matching CPE(s)
 cpe:2.3:a:apache:tomcat:7.0.26:*:*:*:*:*:*:*
     Show Matching CPE(s)
 cpe:2.3:a:apache:tomcat:7.0.27:*:*:*:*:*:*:*
     Show Matching CPE(s)
 cpe:2.3:a:apache:tomcat:7.0.28:*:*:*:*:*:*:*
     Show Matching CPE(s)
 cpe:2.3:a:apache:tomcat:7.0.29:*:*:*:*:*:*:*
     Show Matching CPE(s)
 cpe:2.3:a:apache:tomcat:7.0.30:*:*:*:*:*:*:*
     Show Matching CPE(s)
 cpe:2.3:a:apache:tomcat:7.0.31:*:*:*:*:*:*:*
     Show Matching CPE(s)
 cpe:2.3:a:apache:tomcat:7.0.32:*:*:*:*:*:*:*
     Show Matching CPE(s)
 cpe:2.3:a:apache:tomcat:7.0.33:*:*:*:*:*:*:*
     Show Matching CPE(s)
 cpe:2.3:a:apache:tomcat:7.0.34:*:*:*:*:*:*:*
     Show Matching CPE(s)
 cpe:2.3:a:apache:tomcat:7.0.35:*:*:*:*:*:*:*
     Show Matching CPE(s)
 cpe:2.3:a:apache:tomcat:7.0.36:*:*:*:*:*:*:*
     Show Matching CPE(s)
 cpe:2.3:a:apache:tomcat:7.0.37:*:*:*:*:*:*:*
     Show Matching CPE(s)
 cpe:2.3:a:apache:tomcat:7.0.38:*:*:*:*:*:*:*
     Show Matching CPE(s)
 cpe:2.3:a:apache:tomcat:7.0.39:*:*:*:*:*:*:*
     Show Matching CPE(s)
 cpe:2.3:a:apache:tomcat:7.0.40:*:*:*:*:*:*:*
     Show Matching CPE(s)
 cpe:2.3:a:apache:tomcat:7.0.41:*:*:*:*:*:*:*
     Show Matching CPE(s)
 cpe:2.3:a:apache:tomcat:7.0.42:*:*:*:*:*:*:*
     Show Matching CPE(s)
 cpe:2.3:a:apache:tomcat:7.0.43:*:*:*:*:*:*:*
     Show Matching CPE(s)
 cpe:2.3:a:apache:tomcat:7.0.44:*:*:*:*:*:*:*
     Show Matching CPE(s)
 cpe:2.3:a:apache:tomcat:7.0.45:*:*:*:*:*:*:*
     Show Matching CPE(s)
 cpe:2.3:a:apache:tomcat:7.0.46:*:*:*:*:*:*:*
     Show Matching CPE(s)
 cpe:2.3:a:apache:tomcat:7.0.47:*:*:*:*:*:*:*
     Show Matching CPE(s)
 cpe:2.3:a:apache:tomcat:7.0.48:*:*:*:*:*:*:*
     Show Matching CPE(s)
 cpe:2.3:a:apache:tomcat:7.0.49:*:*:*:*:*:*:*
     Show Matching CPE(s)
 cpe:2.3:a:apache:tomcat:7.0.50:*:*:*:*:*:*:*
     Show Matching CPE(s)
 cpe:2.3:a:apache:tomcat:7.0.52:*:*:*:*:*:*:*
     Show Matching CPE(s)
 cpe:2.3:a:apache:tomcat:7.0.53:*:*:*:*:*:*:*
     Show Matching CPE(s)


Change History

19 change records found - show changes

Quick Info

CVE Dictionary Entry:
CVE-2014-0119
NVD Published Date:
05/31/2014
NVD Last Modified:
04/15/2019