The TransformerFactory in Apache Xalan-Java before 2.7.2 does not properly restrict access to certain properties when FEATURE_SECURE_PROCESSING is enabled, which allows remote attackers to bypass expected restrictions and load arbitrary classes or access external resources via a crafted (1) xalan:content-header, (2) xalan:entities, (3) xslt:content-header, or (4) xslt:entities property, or a Java property that is bound to the XSLT 1.0 system-property function.
CVSS Details
- CVSS 3.1 Base Score: 7.3
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Centos_linux | — | Upgrade xalan-j2-javadocUpgrade xalan-j2Upgrade xalan-j2-demoUpgrade xalan-j2-manualUpgrade xalan-j2-xsltc | Dec 1, 2016 | Apr 15, 2014 |
| Debian | — | Upgrade libxalan2-java | Jul 30, 2024 | Apr 15, 2014 |
| Gentoo Linux | — | Upgrade dev-java/xalan. | Oct 30, 2017 | Apr 15, 2014 |
| Oracle Weblogic | — | Apply the Patch Set Update (PSU) 21984589 for version 10.3.6.0.0.Apply the Patch Set Update (PSU) 21984577 for version 12.1.2.0.0.Apply the Patch Set Update (PSU) 21983457 for version 12.1.3.0.0. | Apr 3, 2018 | Apr 15, 2014 |
| Oracle_linux | — | Upgrade xalan-j2-demoUpgrade xalan-j2Upgrade xalan-j2-manualUpgrade xalan-j2-xsltcUpgrade xalan-j2-javadoc | Oct 16, 2024 | Apr 15, 2014 |
| Red Hat Jboss Eap | — | Upgrade Red Hat JBoss EAP to the latest version | Sep 19, 2024 | Mar 24, 2014 |
| Suse | — | Upgrade xalan-j2-demoUpgrade xalan-j2-javadocUpgrade xalan-j2-manualUpgrade xalan-j2 | Dec 18, 2015 | Apr 15, 2014 |
| Ubuntu | — | Upgrade libxsltc-javaUpgrade libxsltc-java-gcjUpgrade libxalan2-java-gcjUpgrade libxalan2-java | Nov 8, 2024 | Apr 15, 2014 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub