{
  "threat_severity" : "Important",
  "public_date" : "2014-03-24T00:00:00Z",
  "bugzilla" : {
    "description" : "Xalan-Java: insufficient constraints in secure processing feature",
    "id" : "1080248",
    "url" : "https://bugzilla.redhat.com/show_bug.cgi?id=1080248"
  },
  "cvss" : {
    "cvss_base_score" : "6.8",
    "cvss_scoring_vector" : "AV:N/AC:M/Au:N/C:P/I:P/A:P",
    "status" : "verified"
  },
  "cwe" : "CWE-358",
  "details" : [ "The TransformerFactory in Apache Xalan-Java before 2.7.2 does not properly restrict access to certain properties when FEATURE_SECURE_PROCESSING is enabled, which allows remote attackers to bypass expected restrictions and load arbitrary classes or access external resources via a crafted (1) xalan:content-header, (2) xalan:entities, (3) xslt:content-header, or (4) xslt:entities property, or a Java property that is bound to the XSLT 1.0 system-property function.", "It was found that the secure processing feature of Xalan-Java had insufficient restrictions defined for certain properties and features. A remote attacker able to provide Extensible Stylesheet Language Transformations (XSLT) content to be processed by an application using Xalan-Java could use this flaw to bypass the intended constraints of the secure processing feature. Depending on the components available in the classpath, this could lead to arbitrary remote code execution in the context of the application server running the application that uses Xalan-Java." ],
  "affected_release" : [ {
    "product_name" : "Fuse ESB Enterprise 7.1.0",
    "release_date" : "2014-10-09T00:00:00Z",
    "advisory" : "RHSA-2014:1369",
    "cpe" : "cpe:/a:redhat:fuse_esb_enterprise:7.1.0"
  }, {
    "product_name" : "Fuse Management Console 7.1.0",
    "release_date" : "2014-10-09T00:00:00Z",
    "advisory" : "RHSA-2014:1369",
    "cpe" : "cpe:/a:redhat:fuse_management_console:7.1.0"
  }, {
    "product_name" : "Fuse MQ Enterprise 7.1.0",
    "release_date" : "2014-10-09T00:00:00Z",
    "advisory" : "RHSA-2014:1369",
    "cpe" : "cpe:/a:redhat:fuse_mq_enterprise:7.1.0"
  }, {
    "product_name" : "JBoss Enterprise BRMS Platform 5.3",
    "release_date" : "2014-08-05T00:00:00Z",
    "advisory" : "RHSA-2014:1007",
    "cpe" : "cpe:/a:redhat:jboss_enterprise_brms_platform:5.3",
    "package" : "xalan-j2"
  }, {
    "product_name" : "Red Hat Enterprise Linux 5",
    "release_date" : "2014-04-01T00:00:00Z",
    "advisory" : "RHSA-2014:0348",
    "cpe" : "cpe:/o:redhat:enterprise_linux:5",
    "package" : "xalan-j2-0:2.7.0-6jpp.2"
  }, {
    "product_name" : "Red Hat Enterprise Linux 6",
    "release_date" : "2014-04-01T00:00:00Z",
    "advisory" : "RHSA-2014:0348",
    "cpe" : "cpe:/o:redhat:enterprise_linux:6",
    "package" : "xalan-j2-0:2.7.0-9.9.el6_5"
  }, {
    "product_name" : "Red Hat JBoss A-MQ 6.1",
    "release_date" : "2014-10-01T00:00:00Z",
    "advisory" : "RHSA-2014:1351",
    "cpe" : "cpe:/a:redhat:jboss_amq:6.1.0"
  }, {
    "product_name" : "Red Hat JBoss BPMS 6.0",
    "release_date" : "2014-06-30T00:00:00Z",
    "advisory" : "RHSA-2014:0819",
    "cpe" : "cpe:/a:redhat:jboss_bpms:6.0"
  }, {
    "product_name" : "Red Hat JBoss BPMS 6.0",
    "release_date" : "2014-09-23T00:00:00Z",
    "advisory" : "RHSA-2014:1291",
    "cpe" : "cpe:/a:redhat:jboss_bpms:6.0",
    "package" : "xalan-j2"
  }, {
    "product_name" : "Red Hat JBoss BRMS 6.0",
    "release_date" : "2014-06-30T00:00:00Z",
    "advisory" : "RHSA-2014:0818",
    "cpe" : "cpe:/a:redhat:jboss_brms:6.0"
  }, {
    "product_name" : "Red Hat JBoss BRMS 6.0",
    "release_date" : "2014-09-23T00:00:00Z",
    "advisory" : "RHSA-2014:1290",
    "cpe" : "cpe:/a:redhat:jboss_brms:6.0",
    "package" : "xalan-j2"
  }, {
    "product_name" : "Red Hat JBoss Enterprise Application Platform 5.2",
    "release_date" : "2014-06-02T00:00:00Z",
    "advisory" : "RHSA-2014:0590",
    "cpe" : "cpe:/a:redhat:jboss_enterprise_application_platform:5.2.0"
  }, {
    "product_name" : "Red Hat JBoss Enterprise Application Platform 5 for RHEL 4",
    "release_date" : "2014-06-02T00:00:00Z",
    "advisory" : "RHSA-2014:0591",
    "cpe" : "cpe:/a:redhat:jboss_enterprise_application_platform:5::el4",
    "package" : "xalan-j2-0:2.7.1-12_patch_08.ep5.el4"
  }, {
    "product_name" : "Red Hat JBoss Enterprise Application Platform 5 for RHEL 5",
    "release_date" : "2014-06-02T00:00:00Z",
    "advisory" : "RHSA-2014:0591",
    "cpe" : "cpe:/a:redhat:jboss_enterprise_application_platform:5::el5",
    "package" : "xalan-j2-0:2.7.1-12_patch_08.ep5.el5"
  }, {
    "product_name" : "Red Hat JBoss Enterprise Application Platform 5 for RHEL 6",
    "release_date" : "2014-06-02T00:00:00Z",
    "advisory" : "RHSA-2014:0591",
    "cpe" : "cpe:/a:redhat:jboss_enterprise_application_platform:5::el6",
    "package" : "xalan-j2-0:2.7.1-12_patch_08.ep5.el6"
  }, {
    "product_name" : "Red Hat JBoss Enterprise Application Platform 6.2",
    "release_date" : "2014-04-30T00:00:00Z",
    "advisory" : "RHSA-2014:0454",
    "cpe" : "cpe:/a:redhat:jboss_enterprise_application_platform:6.2",
    "package" : "xalan-j2"
  }, {
    "product_name" : "Red Hat JBoss Enterprise Application Platform 6.2 for RHEL 5",
    "release_date" : "2014-04-30T00:00:00Z",
    "advisory" : "RHSA-2014:0453",
    "cpe" : "cpe:/a:redhat:jboss_enterprise_application_platform:6::el5",
    "package" : "xalan-j2-eap6-0:2.7.1-9.redhat_7.1.ep6.el5"
  }, {
    "product_name" : "Red Hat JBoss Enterprise Application Platform 6.2 for RHEL 6",
    "release_date" : "2014-04-30T00:00:00Z",
    "advisory" : "RHSA-2014:0453",
    "cpe" : "cpe:/a:redhat:jboss_enterprise_application_platform:6::el6",
    "package" : "xalan-j2-eap6-0:2.7.1-9.redhat_7.1.ep6.el6"
  }, {
    "product_name" : "Red Hat JBoss Fuse 6.1",
    "release_date" : "2014-10-01T00:00:00Z",
    "advisory" : "RHSA-2014:1351",
    "cpe" : "cpe:/a:redhat:jboss_fuse:6.1.0"
  }, {
    "product_name" : "Red Hat JBoss Fuse Service Works 6.0",
    "release_date" : "2014-12-15T00:00:00Z",
    "advisory" : "RHSA-2014:1995",
    "cpe" : "cpe:/a:redhat:jboss_fuse_service_works:6.0",
    "package" : "xalan-j2"
  }, {
    "product_name" : "Red Hat JBoss Portal 5.2",
    "release_date" : "2014-08-14T00:00:00Z",
    "advisory" : "RHSA-2014:1059",
    "cpe" : "cpe:/a:redhat:jboss_enterprise_portal_platform:5.2.2",
    "package" : "xalan-j2"
  }, {
    "product_name" : "Red Hat JBoss Portal 6.2",
    "release_date" : "2015-05-14T00:00:00Z",
    "advisory" : "RHSA-2015:1009",
    "cpe" : "cpe:/a:redhat:jboss_enterprise_portal_platform:6.2",
    "package" : "xalan-j2"
  }, {
    "product_name" : "Red Hat JBoss SOA Platform 5.3",
    "release_date" : "2015-10-12T00:00:00Z",
    "advisory" : "RHSA-2015:1888",
    "cpe" : "cpe:/a:redhat:jboss_enterprise_soa_platform:5.3",
    "package" : "xalan-j2"
  } ],
  "package_state" : [ {
    "product_name" : "Red Hat Enterprise Linux 7",
    "fix_state" : "Not affected",
    "package_name" : "xalan-j2",
    "cpe" : "cpe:/o:redhat:enterprise_linux:7"
  }, {
    "product_name" : "Red Hat Enterprise Virtualization 3",
    "fix_state" : "Not affected",
    "package_name" : "jasperreports-server-pro",
    "cpe" : "cpe:/a:redhat:enterprise_linux:7::hypervisor"
  }, {
    "product_name" : "Red Hat JBoss Data Grid 6",
    "fix_state" : "Not affected",
    "package_name" : "xalan-j2",
    "cpe" : "cpe:/a:redhat:jboss_data_grid:6"
  }, {
    "product_name" : "Red Hat JBoss Data Virtualization 6",
    "fix_state" : "Not affected",
    "package_name" : "xalan-j2",
    "cpe" : "cpe:/a:redhat:jboss_data_virtualization:6"
  }, {
    "product_name" : "Red Hat JBoss Enterprise Application Platform 4",
    "fix_state" : "Will not fix",
    "package_name" : "xalan-j2",
    "cpe" : "cpe:/a:redhat:jboss_enterprise_application_platform:4"
  }, {
    "product_name" : "Red Hat JBoss Enterprise Web Server 1",
    "fix_state" : "Affected",
    "package_name" : "xalan-j2",
    "cpe" : "cpe:/a:redhat:jboss_enterprise_web_server:1"
  }, {
    "product_name" : "Red Hat JBoss Operations Network 3",
    "fix_state" : "Not affected",
    "package_name" : "xalan-j2",
    "cpe" : "cpe:/a:redhat:jboss_operations_network:3"
  }, {
    "product_name" : "Red Hat JBoss SOA Platform 4",
    "fix_state" : "Will not fix",
    "package_name" : "xalan-j2",
    "cpe" : "cpe:/a:redhat:jboss_enterprise_soa_platform:4"
  } ],
  "references" : [ "https://www.cve.org/CVERecord?id=CVE-2014-0107\nhttps://nvd.nist.gov/vuln/detail/CVE-2014-0107\nhttp://www.ocert.org/advisories/ocert-2014-002.html" ],
  "name" : "CVE-2014-0107",
  "csaw" : false
}