Lucene search

K
redhatRedHatRHSA-2014:1034
HistoryAug 07, 2014 - 12:00 a.m.

(RHSA-2014:1034) Low: tomcat security update

2014-08-0700:00:00
access.redhat.com
18

0.002 Low

EPSS

Percentile

53.6%

Apache Tomcat is a servlet container for the Java Servlet and JavaServer
Pages (JSP) technologies.

It was found that, in certain circumstances, it was possible for a
malicious web application to replace the XML parsers used by Apache Tomcat
to process XSLTs for the default servlet, JSP documents, tag library
descriptors (TLDs), and tag plug-in configuration files. The injected XML
parser(s) could then bypass the limits imposed on XML external entities
and/or gain access to the XML files processed for other web applications
deployed on the same Apache Tomcat instance. (CVE-2014-0119)

All Tomcat users are advised to upgrade to these updated packages, which
contain a backported patch to correct this issue. Tomcat must be restarted
for this update to take effect.