VDB
RHSA-2014%3A1086
RHSA-2014%3A1086
PUBLISHED
CVSS 1.2000000476837158 LOW
It was found that several application-provided XML files, such as web.xml, content.xml, *.tld, *.tagx, and *.jspx, resolved external entities, permitting XML External Entity (XXE) attacks. An attacker able to deploy malicious applications to Tomcat could use this flaw to circumvent security restrictions set by the JSM, and gain access to sensitive information on the system. Note that this flaw only affected deployments in which Tomcat is running applications from untrusted sources, such as in a shared hosting environment.
Risk Scores
CVSS 2.0
1.2000000476837158
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Red Hat | Red Hat JBoss Web Server 2.1 |
Timeline
- Aug 21, 2014 CVE Published
- Apr 29, 2026 Distribution Patch
- Apr 29, 2026 Distribution Patch
- Apr 29, 2026 Security Advisory
- Apr 29, 2026 Security Advisory
- Apr 29, 2026 Security Advisory
- Apr 29, 2026 Security Advisory
- Apr 29, 2026 Security Advisory
- Apr 29, 2026 Security Advisory
- Apr 29, 2026 Security Advisory
- Apr 29, 2026 Security Advisory
- May 14, 2026 CVE Updated
References
- https://access.redhat.com/errata/RHSA-2014:1086 advisory
- https://access.redhat.com/security/updates/classification/#important advisory
- https://access.redhat.com/jbossnetwork/restricted/listSoftware.html?downloadType=distributions&product=webserver&version=2.1.0 advisory
- https://access.redhat.com/documentation/en-US/JBoss_Enterprise_Web_Server/2.1/html/2.1.0_Release_Notes/index.html advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1069911 issue
- https://bugzilla.redhat.com/show_bug.cgi?id=1102038 issue
- https://bugzilla.redhat.com/show_bug.cgi?id=1103593 issue
- https://bugzilla.redhat.com/show_bug.cgi?id=1120596 issue
- https://bugzilla.redhat.com/show_bug.cgi?id=1120601 issue
- https://bugzilla.redhat.com/show_bug.cgi?id=1120603 issue
- https://security.access.redhat.com/data/csaf/v2/advisories/2014/rhsa-2014_1086.json advisory
- https://access.redhat.com/security/cve/CVE-2013-4590 advisory
- https://www.cve.org/CVERecord?id=CVE-2013-4590 advisory
- https://nvd.nist.gov/vuln/detail/CVE-2013-4590 advisory
- https://access.redhat.com/security/cve/CVE-2014-0118 advisory
- https://www.cve.org/CVERecord?id=CVE-2014-0118 advisory
- https://nvd.nist.gov/vuln/detail/CVE-2014-0118 advisory
- http://httpd.apache.org/security/vulnerabilities_24.html advisory
- https://access.redhat.com/security/cve/CVE-2014-0119 advisory
- https://www.cve.org/CVERecord?id=CVE-2014-0119 advisory
…and 17 more