VDB
RHSA-2014:1086
RHSA-2014:1086
PUBLISHED
CVSS 1.2000000476837158 LOW
It was found that several application-provided XML files, such as web.xml, content.xml, *.tld, *.tagx, and *.jspx, resolved external entities, permitting XML External Entity (XXE) attacks. An attacker able to deploy malicious applications to Tomcat could use this flaw to circumvent security restrictions set by the JSM, and gain access to sensitive information on the system. Note that this flaw only affected deployments in which Tomcat is running applications from untrusted sources, such as in a shared hosting environment.
Risk Scores
CVSS 2.0
1.2000000476837158
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Red Hat | Red Hat JBoss Web Server 2.1 |
Timeline
- Aug 21, 2014 CVE Published
- Apr 29, 2026 Distribution Patch
- Apr 29, 2026 Security Advisory
- Apr 29, 2026 Security Advisory
- May 14, 2026 CVE Updated
- May 15, 2026 Distribution Patch
- May 15, 2026 Security Advisory
- May 15, 2026 Security Advisory
- May 15, 2026 Security Advisory
- May 15, 2026 Security Advisory
- May 15, 2026 Security Advisory
- May 15, 2026 Security Advisory
References
- https://access.redhat.com/errata/RHSA-2014:1086 advisory
- https://access.redhat.com/security/updates/classification/#important advisory
- https://access.redhat.com/documentation/en-US/JBoss_Enterprise_Web_Server/2.1/html/2.1.0_Release_Notes/index.html advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1069911 issue
- https://bugzilla.redhat.com/show_bug.cgi?id=1102038 issue
- https://bugzilla.redhat.com/show_bug.cgi?id=1103593 issue
- https://access.redhat.com/security/cve/CVE-2013-4590 advisory
- https://nvd.nist.gov/vuln/detail/CVE-2013-4590 advisory
- https://www.cve.org/CVERecord?id=CVE-2014-0118 advisory
- http://httpd.apache.org/security/vulnerabilities_24.html advisory
- https://access.redhat.com/security/cve/CVE-2014-0119 advisory
- https://www.cve.org/CVERecord?id=CVE-2014-0119 advisory
- https://access.redhat.com/security/cve/CVE-2014-0221 advisory
- https://access.redhat.com/security/cve/CVE-2014-0226 advisory
- https://www.cve.org/CVERecord?id=CVE-2014-0226 advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1109196 issue
- https://www.cve.org/CVERecord?id=CVE-2014-0227 advisory
- https://www.cve.org/CVERecord?id=CVE-2014-0231 advisory
- https://access.redhat.com/jbossnetwork/restricted/listSoftware.html?downloadType=distributions&product=webserver&version=2.1.0 advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1120596 issue
…and 17 more