VDB
RHSA-2014%3A0454
RHSA-2014%3A0454
PUBLISHED
CVSS 6.800000190734863 MEDIUM
It was found that the secure processing feature of Xalan-Java had insufficient restrictions defined for certain properties and features. A remote attacker able to provide Extensible Stylesheet Language Transformations (XSLT) content to be processed by an application using Xalan-Java could use this flaw to bypass the intended constraints of the secure processing feature. Depending on the components available in the classpath, this could lead to arbitrary remote code execution in the context of the application server running the application that uses Xalan-Java.
Risk Scores
CVSS 2.0
6.800000190734863
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Red Hat | Red Hat JBoss Enterprise Application Platform 6.2 |
Timeline
- Apr 30, 2014 CVE Published
- Jan 28, 2026 CVE Updated
- Apr 29, 2026 Distribution Patch
- Apr 29, 2026 Distribution Patch
- Apr 29, 2026 Security Advisory
- Apr 29, 2026 Security Advisory
References
- https://access.redhat.com/errata/RHSA-2014:0454 advisory
- https://access.redhat.com/security/updates/classification/#important advisory
- https://access.redhat.com/jbossnetwork/restricted/listSoftware.html?product=appplatform&downloadType=securityPatches&version=6.2.0 advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1080248 issue
- https://security.access.redhat.com/data/csaf/v2/advisories/2014/rhsa-2014_0454.json advisory
- https://access.redhat.com/security/cve/CVE-2014-0107 advisory
- https://www.cve.org/CVERecord?id=CVE-2014-0107 advisory
- https://nvd.nist.gov/vuln/detail/CVE-2014-0107 advisory
- http://www.ocert.org/advisories/ocert-2014-002.html advisory