Description
The TransformerFactory in Apache Xalan-Java before 2.7.2 does not properly restrict access to certain properties when FEATURE_SECURE_PROCESSING is enabled, which allows remote attackers to bypass expected restrictions and load arbitrary classes or access external resources via a crafted (1) xalan:content-header, (2) xalan:entities, (3) xslt:content-header, or (4) xslt:entities property, or a Java property that is bound to the XSLT 1.0 system-property function.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
Debian DSA |
DSA-2886-1 | libxalan2-java security update |
EUVD |
EUVD-2022-5145 | The TransformerFactory in Apache Xalan-Java before 2.7.2 does not properly restrict access to certain properties when FEATURE_SECURE_PROCESSING is enabled, which allows remote attackers to bypass expected restrictions and load arbitrary classes or access external resources via a crafted (1) xalan:content-header, (2) xalan:entities, (3) xslt:content-header, or (4) xslt:entities property, or a Java property that is bound to the XSLT 1.0 system-property function. |
Github GHSA |
GHSA-rc2w-r4jq-7pfx | Improper Authorization in Apache Xalan-Java |
Ubuntu USN |
USN-2218-1 | Xalan-Java vulnerability |
References
History
Sat, 12 Jul 2025 13:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
epss
|
epss
|
Subscriptions
Apache
Subscribe
Xalan-java
Subscribe
Oracle
Subscribe
Webcenter Sites
Subscribe
Redhat
Subscribe
Enterprise Linux
Subscribe
Fuse Esb Enterprise
Subscribe
Fuse Management Console
Subscribe
Fuse Mq Enterprise
Subscribe
Jboss Amq
Subscribe
Jboss Bpms
Subscribe
Jboss Brms
Subscribe
Jboss Enterprise Application Platform
Subscribe
Jboss Enterprise Brms Platform
Subscribe
Jboss Enterprise Portal Platform
Subscribe
Jboss Enterprise Soa Platform
Subscribe
Jboss Fuse
Subscribe
Jboss Fuse Service Works
Subscribe
Status: PUBLISHED
Assigner: redhat
Published:
Updated: 2024-08-06T09:05:38.816Z
Reserved: 2013-12-03T00:00:00.000Z
Link: CVE-2014-0107
No data.
Status : Deferred
Published: 2014-04-15T23:13:13.070
Modified: 2025-04-12T10:46:40.837
Link: CVE-2014-0107
OpenCVE Enrichment
No data.
Debian DSA
EUVD
Github GHSA
Ubuntu USN