Lucene search

K
f5F5F5:K15429
HistoryOct 14, 2014 - 12:00 a.m.

K15429 : Apache Tomcat vulnerability CVE-2014-0119

2014-10-1400:00:00
my.f5.com
15

AI Score

6.9

Confidence

Low

EPSS

0.002

Percentile

53.5%

Security Advisory Description

Apache Tomcat before 6.0.40, 7.x before 7.0.54, and 8.x before 8.0.6 does not properly constrain the class loader that accesses the XML parser used with an XSLT stylesheet, which allows remote attackers to (1) read arbitrary files via a crafted web application that provides an XML external entity declaration in conjunction with an entity reference, related to an XML External Entity (XXE) issue, or (2) read files associated with different web applications on a single Tomcat instance via a crafted web application. (CVE-2014-0119)

Impact

An attacker may be able to bypass security-manager restrictions by way of a crafted web application. This vulnerability is considered local, as it is exploitable only by an authenticated user accessing the system using the command line.