Apache Standard Taglibs before 1.2.3 allows remote attackers to execute arbitrary code or conduct external XML entity (XXE) attacks via a crafted XSLT extension in a (1) <x:parse> or (2) <x:transform> JSTL XML tag.
CVSS Details
- CVSS 3.1 Base Score: 7.6
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Centos_linux | — | Upgrade jakarta-taglibs-standardUpgrade jakarta-taglibs-standard-javadoc | Dec 1, 2016 | Mar 9, 2015 |
| Ibm Was | — | Upgrade to minimal fix pack levels as required by interim fixes and then apply latest Interim Fix. | Apr 27, 2018 | Mar 9, 2015 |
| Oracle Weblogic | — | Apply the Patch Set Update (PSU) 32832660 for version 12.1.3.0.0.Apply the Patch Set Update (PSU) 32832785 for version 10.3.6.0.0. | Jul 20, 2021 | Mar 9, 2015 |
| Oracle_linux | — | Upgrade jakarta-taglibs-standardUpgrade jakarta-taglibs-standard-javadoc | Jul 22, 2024 | Feb 27, 2015 |
| Red Hat Jboss Eap | — | Upgrade Red Hat JBoss EAP to the latest version | Sep 19, 2024 | Feb 27, 2015 |
| Redhat_linux | — | No solution exists | Jul 9, 2025 | Feb 27, 2015 |
| Suse | — | Upgrade jakarta-taglibs-standard-javadocUpgrade jakarta-taglibs-standard | Dec 18, 2015 | Mar 9, 2015 |
| Ubuntu | — | Upgrade libjstl1.1-javaUpgrade libjakarta-taglibs-standard-java | Nov 8, 2024 | Mar 9, 2015 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub