Description
The TransformerFactory in Apache Xalan-Java before 2.7.2 does not properly restrict access to certain properties when FEATURE_SECURE_PROCESSING is enabled, which allows remote attackers to bypass expected restrictions and load arbitrary classes or access external resources via a crafted (1) xalan:content-header, (2) xalan:entities, (3) xslt:content-header, or (4) xslt:entities property, or a Java property that is bound to the XSLT 1.0 system-property function.
Analysis and contextual insights are available on OpenCVE Cloud.
Remediation
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
Debian DSA |
DSA-2886-1 | libxalan2-java security update |
EUVD |
EUVD-2022-5145 | The TransformerFactory in Apache Xalan-Java before 2.7.2 does not properly restrict access to certain properties when FEATURE_SECURE_PROCESSING is enabled, which allows remote attackers to bypass expected restrictions and load arbitrary classes or access external resources via a crafted (1) xalan:content-header, (2) xalan:entities, (3) xslt:content-header, or (4) xslt:entities property, or a Java property that is bound to the XSLT 1.0 system-property function. |
Github GHSA |
GHSA-rc2w-r4jq-7pfx | Improper Authorization in Apache Xalan-Java |
Ubuntu USN |
USN-2218-1 | Xalan-Java vulnerability |
References
History
Sat, 12 Jul 2025 13:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
epss
|
epss
|
Subscriptions
Apache
Subscribe
Xalan-java
Subscribe
Oracle
Subscribe
Webcenter Sites
Subscribe
Redhat
Subscribe
Enterprise Linux
Subscribe
Fuse Esb Enterprise
Subscribe
Fuse Management Console
Subscribe
Fuse Mq Enterprise
Subscribe
Jboss Amq
Subscribe
Jboss Bpms
Subscribe
Jboss Brms
Subscribe
Jboss Enterprise Application Platform
Subscribe
Jboss Enterprise Brms Platform
Subscribe
Jboss Enterprise Portal Platform
Subscribe
Jboss Enterprise Soa Platform
Subscribe
Jboss Fuse
Subscribe
Jboss Fuse Service Works
Subscribe
Status: PUBLISHED
Assigner: redhat
Published:
Updated: 2024-08-06T09:05:38.816Z
Reserved: 2013-12-03T00:00:00.000Z
Link: CVE-2014-0107
No data.
Status : Modified
Published: 2014-04-15T23:13:13.070
Modified: 2026-05-06T22:30:45.220
Link: CVE-2014-0107
OpenCVE Enrichment
No data.
Debian DSA
EUVD
Github GHSA
Ubuntu USN