The TransformerFactory in Apache Xalan-Java before 2.7.2 does not properly restrict access to certain properties when FEATURE_SECURE_PROCESSING is enabled, which allows remote attackers to bypass expected restrictions and load arbitrary classes or access external resources via a crafted (1) xalan:content-header, (2) xalan:entities, (3) xslt:content-header, or (4) xslt:entities property, or a Java property that is bound to the XSLT 1.0 system-property function.
Project Subscriptions
| Vendors | Products |
|---|---|
|
Apache
Subscribe
|
Xalan-java
Subscribe
|
|
Oracle
Subscribe
|
Webcenter Sites
Subscribe
|
|
Redhat
Subscribe
|
Enterprise Linux
Subscribe
Fuse Esb Enterprise
Subscribe
Fuse Management Console
Subscribe
Fuse Mq Enterprise
Subscribe
Jboss Amq
Subscribe
Jboss Bpms
Subscribe
Jboss Brms
Subscribe
Jboss Enterprise Application Platform
Subscribe
Jboss Enterprise Brms Platform
Subscribe
Jboss Enterprise Portal Platform
Subscribe
Jboss Enterprise Soa Platform
Subscribe
Jboss Fuse
Subscribe
Jboss Fuse Service Works
Subscribe
|
Advisories
| Source | ID | Title |
|---|---|---|
Debian DSA |
DSA-2886-1 | libxalan2-java security update |
EUVD |
EUVD-2022-5145 | The TransformerFactory in Apache Xalan-Java before 2.7.2 does not properly restrict access to certain properties when FEATURE_SECURE_PROCESSING is enabled, which allows remote attackers to bypass expected restrictions and load arbitrary classes or access external resources via a crafted (1) xalan:content-header, (2) xalan:entities, (3) xslt:content-header, or (4) xslt:entities property, or a Java property that is bound to the XSLT 1.0 system-property function. |
Github GHSA |
GHSA-rc2w-r4jq-7pfx | Improper Authorization in Apache Xalan-Java |
Ubuntu USN |
USN-2218-1 | Xalan-Java vulnerability |
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Sat, 12 Jul 2025 13:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
epss
|
epss
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: redhat
Published:
Updated: 2024-08-06T09:05:38.816Z
Reserved: 2013-12-03T00:00:00
Link: CVE-2014-0107
No data.
Status : Deferred
Published: 2014-04-15T23:13:13.070
Modified: 2025-04-12T10:46:40.837
Link: CVE-2014-0107
OpenCVE Enrichment
No data.
Debian DSA
EUVD
Github GHSA
Ubuntu USN