CVE-2015-0254

Apache Standard Taglibs < 1.2.3 - Remote Code Execution and XML External Entity Injection via JSTL XML Tags

Title source: llm
STIX 2.1

Description

Apache Standard Taglibs before 1.2.3 allows remote attackers to execute arbitrary code or conduct external XML entity (XXE) attacks via a crafted XSLT extension in a (1) <x:parse> or (2) <x:transform> JSTL XML tag.

References (23)

Core 23
Core References
Third Party Advisory, VDB Entry mailing-list x_refsource_bugtraq
http://www.securityfocus.com/archive/1/534772/100/0/threaded
Vendor Advisory vendor-advisory x_refsource_redhat
http://rhn.redhat.com/errata/RHSA-2016-1841.html
Vendor Advisory vendor-advisory x_refsource_redhat
http://rhn.redhat.com/errata/RHSA-2016-1838.html
Vendor Advisory vendor-advisory x_refsource_redhat
http://rhn.redhat.com/errata/RHSA-2015-1695.html
Vendor Advisory vendor-advisory x_refsource_redhat
http://rhn.redhat.com/errata/RHSA-2016-1839.html
Vendor Advisory vendor-advisory x_refsource_redhat
http://rhn.redhat.com/errata/RHSA-2016-1840.html
Third Party Advisory vendor-advisory x_refsource_ubuntu
http://www.ubuntu.com/usn/USN-2551-1
Vendor Advisory vendor-advisory x_refsource_redhat
https://access.redhat.com/errata/RHSA-2016:1376
Mailing List vendor-advisory x_refsource_suse
http://lists.opensuse.org/opensuse-updates/2015-10/msg00033.html
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/72809
Third Party Advisory, VDB Entry vdb-entry x_refsource_sectrack
http://www.securitytracker.com/id/1034934

Scores

EPSS 0.0381
EPSS Percentile 88.3%

Details

Status published
Products (5)
apache/standard_taglibs < 1.2.1
canonical/ubuntu_linux 14.04
canonical/ubuntu_linux 14.10
org.apache.taglibs/taglibs-standard 0 - 1.2.3Maven
org.apache.taglibs/taglibs-standard-impl 0 - 1.2.3Maven
Published Mar 09, 2015
Tracked Since Feb 18, 2026