Back

MEDIUM

tomcat: information disclosure via XXE when running untrusted web applications

Published Feb 26, 2014

Description

Apache Tomcat before 6.0.39, 7.x before 7.0.50, and 8.x before 8.0.0-RC10 allows attackers to obtain "Tomcat internals" information by leveraging the presence of an untrusted web application with a context.xml, web.xml, *.jspx, *.tagx, or *.tld XML document containing an external entity declaration in conjunction with an entity reference, related to an XML External Entity (XXE) issue.

Affected products

Remediation

Red Hat statement

This issue did not affect JBoss Web, as shipped with various Red Hat JBoss products. This issue does affect Tomcat 5 as shipped by Red Hat Enterprise Linux 5. The risks in breaking compatibility associated with fixing this flaw outweigh the benefits of the fix, therefore Red Hat does not plan to fix this flaw in Red Hat Enterprise Linux 5. Additionally, note that Red Hat Enterprise Linux 5 is currently in reduced support phase, receiving only Critical security updates. For additional information, refer to the Red Hat Enterprise Linux Life Cycle: https://access.redhat.com/site/support/policy/updates/errata#Production_3_Phase

Metrics

References (44)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner redhat
Published Feb 26, 2014
Updated Aug 6, 2024
Reserved Jun 12, 2013
NVD
Status Modified
Modified Jun 16, 2026
Red Hat
Severity Low
Public date Feb 25, 2014
GHSA-87W9-X2C3-HRJJ