CVE-2014-0107

UnknownEPSS 13.70%

Last modified

CVE-2014-0107 is a vulnerability of currently unknown severity. The TransformerFactory in Apache Xalan-Java before 2.7.2 does not properly restrict access to certain properties when FEATURE_SECURE_PROCESSING is enabled, which allows remote attackers to bypass expected restrictions and load arbitrary classes or access external resources via a crafted (1) xalan:content-header, (2) xalan:entities, (3) xslt:content-header, or (4) xslt:entities property, or a Java property that is bound to the XSLT 1.0 system-property function.. EPSS estimates a 13.70% chance of exploitation in the next 30 days.

Description

The TransformerFactory in Apache Xalan-Java before 2.7.2 does not properly restrict access to certain properties when FEATURE_SECURE_PROCESSING is enabled, which allows remote attackers to bypass expected restrictions and load arbitrary classes or access external resources via a crafted (1) xalan:content-header, (2) xalan:entities, (3) xslt:content-header, or (4) xslt:entities property, or a Java property that is bound to the XSLT 1.0 system-property function.

Metrics

EPSS Probability
13.70%

96.0th percentile

Probability of exploitation in the next 30 days. Learn more

Weakness Enumeration

Affected Software

VendorProductVersions
ApacheXalan-Java<= 2.7.1
ApacheXalan-Java1.0.0
ApacheXalan-Java2.0.0
ApacheXalan-Java2.0.1
ApacheXalan-Java2.1.0
ApacheXalan-Java2.2.0
ApacheXalan-Java2.4.0
ApacheXalan-Java2.4.1
ApacheXalan-Java2.5.0
ApacheXalan-Java2.5.1
ApacheXalan-Java2.5.2
ApacheXalan-Java2.6.0
ApacheXalan-Java2.7.0
OracleWebcenter Sites7.6.2
OracleWebcenter Sites11.1.1.8.0

References

Timeline

Published
Last Modified
Status
Modified

Frequently Asked Questions

What is CVE-2014-0107?
The TransformerFactory in Apache Xalan-Java before 2.7.2 does not properly restrict access to certain properties when FEATURE_SECURE_PROCESSING is enabled, which allows remote attackers to bypass expected restrictions and load arbitrary classes or access external resources via a crafted (1) xalan:content-header, (2) xalan:entities, (3) xslt:content-header, or (4) xslt:entities property, or a Java property that is bound to the XSLT 1.0 system-property function.
How severe is CVE-2014-0107?
Severity scoring for CVE-2014-0107 is pending analysis. The EPSS model estimates a 13.70% probability of exploitation in the next 30 days.
How do I fix CVE-2014-0107?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.

Are you affected by CVE-2014-0107?

Run a free Strix scan to check your systems for this vulnerability.

Scan your code now

Source: NVD / NIST