Description
Apache Tomcat before 6.0.40, 7.x before 7.0.54, and 8.x before 8.0.6 does not properly constrain the class loader that accesses the XML parser used with an XSLT stylesheet, which allows remote attackers to (1) read arbitrary files via a crafted web application that provides an XML external entity declaration in conjunction with an entity reference, related to an XML External Entity (XXE) issue, or (2) read files associated with different web applications on a single Tomcat instance via a crafted web application.
References (51)
Core 51
Core References
Patch x_refsource_confirm
http://svn.apache.org/viewvc?view=revision&revision=1590036
Patch x_refsource_confirm
http://svn.apache.org/viewvc?view=revision&revision=1590028
Patch x_refsource_confirm
http://svn.apache.org/viewvc?view=revision&revision=1589992
Patch x_refsource_confirm
http://svn.apache.org/viewvc?view=revision&revision=1589997
Patch x_refsource_confirm
http://svn.apache.org/viewvc?view=revision&revision=1589985
Patch x_refsource_confirm
http://svn.apache.org/viewvc?view=revision&revision=1593815
Patch x_refsource_confirm
http://svn.apache.org/viewvc?view=revision&revision=1589990
Patch x_refsource_confirm
http://svn.apache.org/viewvc?view=revision&revision=1593821
Vendor Advisory vendor-advisory
x_refsource_redhat
http://rhn.redhat.com/errata/RHSA-2015-0765.html
Vendor Advisory vendor-advisory
x_refsource_redhat
http://rhn.redhat.com/errata/RHSA-2015-0675.html
Vendor Advisory vendor-advisory
x_refsource_redhat
http://rhn.redhat.com/errata/RHSA-2015-0720.html
Various Sources x_refsource_confirm
https://h20564.www2.hpe.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c04851013
Mailing List mailing-list
x_refsource_mlist
https://lists.apache.org/thread.html/37220405a377c0182d2afdbc36461c4783b2930fbeae3a17f1333113%40%3Cdev.tomcat.apache.org%3E
Third Party Advisory x_refsource_confirm
http://advisories.mageia.org/MGASA-2014-0268.html
Patch x_refsource_confirm
http://svn.apache.org/viewvc?view=revision&revision=1589837
Vendor Advisory vendor-advisory
x_refsource_ubuntu
http://www.ubuntu.com/usn/USN-2654-1
Third Party Advisory third-party-advisory
x_refsource_secunia
http://secunia.com/advisories/59732
Vendor Advisory x_refsource_confirm
http://www.vmware.com/security/advisories/VMSA-2014-0012.html
Various Sources x_refsource_confirm
http://www-01.ibm.com/support/docview.wss?uid=swg21681528
Vendor Advisory vendor-advisory
x_refsource_mandriva
http://www.mandriva.com/security/advisories?name=MDVSA-2015:052
Vendor Advisory vendor-advisory
x_refsource_mandriva
http://www.mandriva.com/security/advisories?name=MDVSA-2015:084
Third Party Advisory vendor-advisory
x_refsource_debian
http://www.debian.org/security/2016/dsa-3530
Patch x_refsource_confirm
http://svn.apache.org/viewvc?view=revision&revision=1589983
Mailing List vendor-advisory
x_refsource_hp
http://marc.info/?l=bugtraq&m=141017844705317&w=2
Vendor Advisory x_refsource_confirm
http://tomcat.apache.org/security-7.html
Third Party Advisory, VDB Entry mailing-list
x_refsource_bugtraq
http://www.securityfocus.com/archive/1/534161/100/0/threaded
Vendor Advisory vendor-advisory
x_refsource_mandriva
http://www.mandriva.com/security/advisories?name=MDVSA-2015:053
Patch x_refsource_confirm
http://svn.apache.org/viewvc?view=revision&revision=1588199
Vendor Advisory x_refsource_confirm
http://www.oracle.com/technetwork/security-advisory/cpuoct2016-2881722.html
Vendor Advisory x_refsource_confirm
http://tomcat.apache.org/security-8.html
Various Sources x_refsource_confirm
http://www-01.ibm.com/support/docview.wss?uid=swg21678231
Patch x_refsource_confirm
http://svn.apache.org/viewvc?view=revision&revision=1589980
Patch x_refsource_confirm
http://svn.apache.org/viewvc?view=revision&revision=1589640
Vendor Advisory x_refsource_confirm
http://tomcat.apache.org/security-6.html
Vendor Advisory x_refsource_confirm
http://www.oracle.com/technetwork/topics/security/cpujul2014-1972956.html
Third Party Advisory third-party-advisory
x_refsource_secunia
http://secunia.com/advisories/59873
Mailing List mailing-list
x_refsource_fulldisc
http://seclists.org/fulldisclosure/2014/May/141
Mailing List mailing-list
x_refsource_fulldisc
http://seclists.org/fulldisclosure/2014/Dec/23
Mailing List vendor-advisory
x_refsource_hp
http://marc.info/?l=bugtraq&m=144498216801440&w=2
Vendor Advisory x_refsource_confirm
http://www.oracle.com/technetwork/topics/security/cpuoct2014-1972960.html
Patch x_refsource_confirm
http://svn.apache.org/viewvc?view=revision&revision=1588193
Third Party Advisory, VDB Entry vdb-entry
x_refsource_bid
http://www.securityfocus.com/bid/67669
Third Party Advisory, VDB Entry vdb-entry
x_refsource_sectrack
http://www.securitytracker.com/id/1030298
Third Party Advisory vendor-advisory
x_refsource_debian
http://www.debian.org/security/2016/dsa-3552
Third Party Advisory third-party-advisory
x_refsource_secunia
http://secunia.com/advisories/60729
Mailing List mailing-list
x_refsource_mlist
https://lists.apache.org/thread.html/b8a1bf18155b552dcf9a928ba808cbadad84c236d85eab3033662cfb%40%3Cdev.tomcat.apache.org%3E
Mailing List mailing-list
x_refsource_mlist
https://lists.apache.org/thread.html/39ae1f0bd5867c15755a6f959b271ade1aea04ccdc3b2e639dcd903b%40%3Cdev.tomcat.apache.org%3E
Mailing List mailing-list
x_refsource_mlist
https://lists.apache.org/thread.html/b84ad1258a89de5c9c853c7f2d3ad77e5b8b2930be9e132d5cef6b95%40%3Cdev.tomcat.apache.org%3E
Mailing List mailing-list
x_refsource_mlist
https://lists.apache.org/thread.html/r03c597a64de790ba42c167efacfa23300c3d6c9fe589ab87fe02859c%40%3Cdev.tomcat.apache.org%3E
Mailing List mailing-list
x_refsource_mlist
https://lists.apache.org/thread.html/r9136ff5b13e4f1941360b5a309efee2c114a14855578c3a2cbe5d19c%40%3Cdev.tomcat.apache.org%3E
Mailing List mailing-list
x_refsource_mlist
https://lists.apache.org/thread.html/r587e50b86c1a96ee301f751d50294072d142fd6dc08a8987ae9f3a9b%40%3Cdev.tomcat.apache.org%3E
Scores
EPSS
0.0435
EPSS Percentile
89.1%
Details
CWE
CWE-264
Status
published
Products (37)
apache/tomcat
8.0.0 rc1 (4 CPE variants)
apache/tomcat
8.0.1
apache/tomcat
8.0.3
apache/tomcat
8.0.5
apache/tomcat
6
apache/tomcat
6.0
apache/tomcat
6.0.0 (2 CPE variants)
apache/tomcat
6.0.1 (2 CPE variants)
apache/tomcat
6.0.2 (3 CPE variants)
apache/tomcat
6.0.3
... and 27 more
Published
May 31, 2014
Tracked Since
Feb 18, 2026