Xalan-Java: insufficient constraints in secure processing feature
Published Apr 15, 2014
7.5
HIGHCVSS 2.0
EPSS 13.81%
Description
The TransformerFactory in Apache Xalan-Java before 2.7.2 does not properly restrict access to certain properties when FEATURE_SECURE_PROCESSING is enabled, which allows remote attackers to bypass expected restrictions and load arbitrary classes or access external resources via a crafted (1) xalan:content-header, (2) xalan:entities, (3) xslt:content-header, or (4) xslt:entities property, or a Java property that is bound to the XSLT 1.0 system-property function.
Affected products
No data.
Configuration 1
- ≤ 2.7.1
- 1.0.0
- 2.0.0
- 2.0.1
- 2.1.0
- 2.2.0
- 2.4.0
- 2.4.1
- 2.5.0
- 2.5.1
- 2.5.2
- 2.6.0
- 2.7.0
Configuration 2
- 7.6.2
- 11.1.1.8.0
No data.
Fuse ESB Enterprise 7.1.0
n/a
Fixed · RHSA-2014:1369
Fuse MQ Enterprise 7.1.0
n/a
Fixed · RHSA-2014:1369
Fuse Management Console 7.1.0
n/a
Fixed · RHSA-2014:1369
JBoss Enterprise BRMS Platform 5.3
xalan-j2
Fixed · RHSA-2014:1007
Red Hat Enterprise Linux 5
xalan-j2-0:2.7.0-6jpp.2
Fixed · RHSA-2014:0348
Red Hat Enterprise Linux 6
xalan-j2-0:2.7.0-9.9.el6_5
Fixed · RHSA-2014:0348
Red Hat JBoss A-MQ 6.1
n/a
Fixed · RHSA-2014:1351
Red Hat JBoss BPMS 6.0
n/a
Fixed · RHSA-2014:0819
Red Hat JBoss BPMS 6.0
xalan-j2
Fixed · RHSA-2014:1291
Red Hat JBoss BRMS 6.0
n/a
Fixed · RHSA-2014:0818
Red Hat JBoss BRMS 6.0
xalan-j2
Fixed · RHSA-2014:1290
Red Hat JBoss Enterprise Application Platform 5 for RHEL 5
xalan-j2-0:2.7.1-12_patch_08.ep5.el5
Fixed · RHSA-2014:0591
Red Hat JBoss Enterprise Application Platform 5 for RHEL 6
xalan-j2-0:2.7.1-12_patch_08.ep5.el6
Fixed · RHSA-2014:0591
Red Hat JBoss Enterprise Application Platform 5.2
n/a
Fixed · RHSA-2014:0590
Red Hat JBoss Enterprise Application Platform 6.2
xalan-j2
Fixed · RHSA-2014:0454
Red Hat JBoss Enterprise Application Platform 6.2 for RHEL 5
xalan-j2-eap6-0:2.7.1-9.redhat_7.1.ep6.el5
Fixed · RHSA-2014:0453
Red Hat JBoss Enterprise Application Platform 6.2 for RHEL 6
xalan-j2-eap6-0:2.7.1-9.redhat_7.1.ep6.el6
Fixed · RHSA-2014:0453
Red Hat JBoss Fuse 6.1
n/a
Fixed · RHSA-2014:1351
Red Hat JBoss Fuse Service Works 6.0
xalan-j2
Fixed · RHSA-2014:1995
Red Hat JBoss Portal 5.2
xalan-j2
Fixed · RHSA-2014:1059
Red Hat JBoss Portal 6.2
xalan-j2
Fixed · RHSA-2015:1009
Red Hat JBoss SOA Platform 5.3
xalan-j2
Fixed · RHSA-2015:1888
Red Hat Enterprise Linux 7
xalan-j2
Not affected
Red Hat Enterprise Virtualization 3
jasperreports-server-pro
Not affected
Red Hat JBoss Data Grid 6
xalan-j2
Not affected
Red Hat JBoss Data Virtualization 6
xalan-j2
Not affected
Red Hat JBoss Enterprise Application Platform 4
xalan-j2
Will not fix
Red Hat JBoss Enterprise Web Server 1
xalan-j2
Affected
Red Hat JBoss Operations Network 3
xalan-j2
Not affected
Red Hat JBoss SOA Platform 4
xalan-j2
Will not fix
| Product | Package | State | Advisory |
|---|---|---|---|
| Fuse ESB Enterprise 7.1.0 | n/a | Fixed | RHSA-2014:1369 |
| Fuse MQ Enterprise 7.1.0 | n/a | Fixed | RHSA-2014:1369 |
| Fuse Management Console 7.1.0 | n/a | Fixed | RHSA-2014:1369 |
| JBoss Enterprise BRMS Platform 5.3 | xalan-j2 | Fixed | RHSA-2014:1007 |
| Red Hat Enterprise Linux 5 | xalan-j2-0:2.7.0-6jpp.2 | Fixed | RHSA-2014:0348 |
| Red Hat Enterprise Linux 6 | xalan-j2-0:2.7.0-9.9.el6_5 | Fixed | RHSA-2014:0348 |
| Red Hat JBoss A-MQ 6.1 | n/a | Fixed | RHSA-2014:1351 |
| Red Hat JBoss BPMS 6.0 | n/a | Fixed | RHSA-2014:0819 |
| Red Hat JBoss BPMS 6.0 | xalan-j2 | Fixed | RHSA-2014:1291 |
| Red Hat JBoss BRMS 6.0 | n/a | Fixed | RHSA-2014:0818 |
| Red Hat JBoss BRMS 6.0 | xalan-j2 | Fixed | RHSA-2014:1290 |
| Red Hat JBoss Enterprise Application Platform 5 for RHEL 5 | xalan-j2-0:2.7.1-12_patch_08.ep5.el5 | Fixed | RHSA-2014:0591 |
| Red Hat JBoss Enterprise Application Platform 5 for RHEL 6 | xalan-j2-0:2.7.1-12_patch_08.ep5.el6 | Fixed | RHSA-2014:0591 |
| Red Hat JBoss Enterprise Application Platform 5.2 | n/a | Fixed | RHSA-2014:0590 |
| Red Hat JBoss Enterprise Application Platform 6.2 | xalan-j2 | Fixed | RHSA-2014:0454 |
| Red Hat JBoss Enterprise Application Platform 6.2 for RHEL 5 | xalan-j2-eap6-0:2.7.1-9.redhat_7.1.ep6.el5 | Fixed | RHSA-2014:0453 |
| Red Hat JBoss Enterprise Application Platform 6.2 for RHEL 6 | xalan-j2-eap6-0:2.7.1-9.redhat_7.1.ep6.el6 | Fixed | RHSA-2014:0453 |
| Red Hat JBoss Fuse 6.1 | n/a | Fixed | RHSA-2014:1351 |
| Red Hat JBoss Fuse Service Works 6.0 | xalan-j2 | Fixed | RHSA-2014:1995 |
| Red Hat JBoss Portal 5.2 | xalan-j2 | Fixed | RHSA-2014:1059 |
| Red Hat JBoss Portal 6.2 | xalan-j2 | Fixed | RHSA-2015:1009 |
| Red Hat JBoss SOA Platform 5.3 | xalan-j2 | Fixed | RHSA-2015:1888 |
| Red Hat Enterprise Linux 7 | xalan-j2 | Not affected | n/a |
| Red Hat Enterprise Virtualization 3 | jasperreports-server-pro | Not affected | n/a |
| Red Hat JBoss Data Grid 6 | xalan-j2 | Not affected | n/a |
| Red Hat JBoss Data Virtualization 6 | xalan-j2 | Not affected | n/a |
| Red Hat JBoss Enterprise Application Platform 4 | xalan-j2 | Will not fix | n/a |
| Red Hat JBoss Enterprise Web Server 1 | xalan-j2 | Affected | n/a |
| Red Hat JBoss Operations Network 3 | xalan-j2 | Not affected | n/a |
| Red Hat JBoss SOA Platform 4 | xalan-j2 | Will not fix | n/a |
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Metrics
No CVSS v4.0 score for this CVE.
No CVSS v3.1 score for this CVE.
No CVSS v3.0 score for this CVE.
AV:N/AC:L/Au:N/C:P/I:P/A:P
This CVE is not in the KEV list.
No CISA SSVC assessment for this CVE yet.
Estimated probability of exploitation in the wild in the next 30 days (FIRST EPSS). As of Oct 1, 2026.
Score over time
2022–2026- EPSS v2
- EPSS v3
- EPSS v4
- EPSS v5
Percentile over time
- EPSS v2
- EPSS v3
- EPSS v4
- EPSS v5
Table of values (19 key points)
Flat stretches are collapsed; showing up to 120 newest points.
| Date | Score | Percentile | Model |
|---|---|---|---|
| Oct 1, 2026 | 13.81% (0.13809) | 96.41th | v5 (v2026.06.15) |
| Jun 15, 2026 | 13.70% (0.13700) | 96.00th | v5 (v2026.06.15) |
| May 24, 2026 | 5.86% (0.05863) | 90.67th | v4 (v2025.03.14) |
| May 18, 2026 | 9.01% (0.09006) | 92.70th | v4 (v2025.03.14) |
| May 13, 2026 | 11.68% (0.11682) | 93.75th | v4 (v2025.03.14) |
| Mar 13, 2026 | 8.85% (0.08846) | 92.42th | v4 (v2025.03.14) |
| Jan 26, 2026 | 7.30% (0.07301) | 91.43th | v4 (v2025.03.14) |
| May 18, 2025 | 5.67% (0.05673) | 89.88th | v4 (v2025.03.14) |
| May 17, 2025 | 6.91% (0.06906) | 90.88th | v4 (v2025.03.14) |
| Mar 30, 2025 | 5.67% (0.05673) | 89.44th | v4 (v2025.03.14) |
| Mar 29, 2025 | 12.46% (0.12461) | 89.84th | v4 (v2025.03.14) |
| Mar 17, 2025 | 5.67% (0.05673) | 89.70th | v4 (v2025.03.14) |
| Dec 17, 2024 | 1.94% (0.01939) | 88.35th | v3 (v2023.03.01) |
| Feb 8, 2024 | 0.54% (0.00544) | 76.69th | v3 (v2023.03.01) |
| May 8, 2023 | 0.54% (0.00544) | 73.97th | v3 (v2023.03.01) |
| Mar 7, 2023 | 0.77% (0.00771) | 78.47th | v3 (v2023.03.01) |
| Mar 6, 2023 | 7.34% (0.07344) | 92.59th | v2 (v2022.01.01) |
| Apr 1, 2022 | 7.34% (0.07344) | 91.87th | v2 (v2022.01.01) |
| Feb 4, 2022 | 7.34% (0.07344) | 80.64th | v2 (v2022.01.01) |
References (48)
- http://rhn.redhat.com/errata/RHSA-2014-0348.html vendor-advisoryx_refsource_REDHAT
- http://rhn.redhat.com/errata/RHSA-2014-1351.html vendor-advisoryx_refsource_REDHAT
- http://rhn.redhat.com/errata/RHSA-2015-1888.html vendor-advisoryx_refsource_REDHAT
- http://secunia.com/advisories/57563 third-party-advisoryx_refsource_SECUNIA
- http://secunia.com/advisories/59036 third-party-advisoryx_refsource_SECUNIA
- http://secunia.com/advisories/59151 third-party-advisoryx_refsource_SECUNIA
- http://secunia.com/advisories/59247 third-party-advisoryx_refsource_SECUNIA
- http://secunia.com/advisories/59290 third-party-advisoryx_refsource_SECUNIA
- http://secunia.com/advisories/59291 third-party-advisoryx_refsource_SECUNIA
- http://secunia.com/advisories/59369 third-party-advisoryx_refsource_SECUNIA
- http://secunia.com/advisories/59515 third-party-advisoryx_refsource_SECUNIA
- http://secunia.com/advisories/59711 third-party-advisoryx_refsource_SECUNIA
- http://secunia.com/advisories/60502 third-party-advisoryx_refsource_SECUNIA
- http://svn.apache.org/viewvc?view=revision&revision=1581058 x_refsource_CONFIRMPatch
- http://www-01.ibm.com/support/docview.wss?uid=swg21674334 x_refsource_CONFIRM
- http://www-01.ibm.com/support/docview.wss?uid=swg21676093 x_refsource_CONFIRM
- http://www-01.ibm.com/support/docview.wss?uid=swg21677145 x_refsource_CONFIRM
- http://www-01.ibm.com/support/docview.wss?uid=swg21680703 x_refsource_CONFIRM
- http://www-01.ibm.com/support/docview.wss?uid=swg21681933 x_refsource_CONFIRM
- http://www.debian.org/security/2014/dsa-2886 vendor-advisoryx_refsource_DEBIAN
- http://www.ibm.com/support/docview.wss?uid=swg21677967 x_refsource_CONFIRM
- http://www.ocert.org/advisories/ocert-2014-002.html x_refsource_MISCUS Government Resource
- http://www.oracle.com/technetwork/security-advisory/cpuoct2017-3236626.html x_refsource_CONFIRM
- http://www.oracle.com/technetwork/topics/security/cpujan2016-2367955.html x_refsource_CONFIRMPatchVendor Advisory
- http://www.securityfocus.com/bid/66397 vdb-entryx_refsource_BID
- http://www.securitytracker.com/id/1034711 vdb-entryx_refsource_SECTRACK
- http://www.securitytracker.com/id/1034716 vdb-entryx_refsource_SECTRACK
- https://access.redhat.com/security/cve/CVE-2014-0107 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1080248 Issue Tracking
- https://exchange.xforce.ibmcloud.com/vulnerabilities/92023 vdb-entryx_refsource_XF
- https://github.com/advisories/GHSA-rc2w-r4jq-7pfx Advisory
- https://h20566.www2.hpe.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c05324755 x_refsource_CONFIRM
- https://issues.apache.org/jira/browse/XALANJ-2435 x_refsource_CONFIRM
- https://lists.apache.org/thread.html/519eb0fd45642dcecd9ff74cb3e71c20a4753f7d82e2f07864b5108f%40%3Cdev.drill.apache.org%3E mailing-listx_refsource_MLIST
- https://lists.apache.org/thread.html/519eb0fd45642dcecd9ff74cb3e71c20a4753f7d82e2f07864b5108f@%3Cdev.drill.apache.org%3E
- https://lists.apache.org/thread.html/b0656d359c7d40ec9f39c8cc61bca66802ef9a2a12ee199f5b0c1442%40%3Cdev.drill.apache.org%3E mailing-listx_refsource_MLIST
- https://lists.apache.org/thread.html/b0656d359c7d40ec9f39c8cc61bca66802ef9a2a12ee199f5b0c1442@%3Cdev.drill.apache.org%3E
- https://lists.apache.org/thread.html/r0c00afcab8f238562e27b3ae7b8af1913c62bc60838fb8b34c19e26b%40%3Cdev.tomcat.apache.org%3E mailing-listx_refsource_MLIST
- https://lists.apache.org/thread.html/r0c00afcab8f238562e27b3ae7b8af1913c62bc60838fb8b34c19e26b@%3Cdev.tomcat.apache.org%3E
- https://lists.apache.org/thread.html/r2900489bc665a2e32d021bb21f6ce2cb8e6bb5973490eebb9a346bca%40%3Cdev.tomcat.apache.org%3E mailing-listx_refsource_MLIST
- https://lists.apache.org/thread.html/r2900489bc665a2e32d021bb21f6ce2cb8e6bb5973490eebb9a346bca@%3Cdev.tomcat.apache.org%3E
- https://nvd.nist.gov/vuln/detail/CVE-2014-0107
- https://security.gentoo.org/glsa/201604-02 vendor-advisoryx_refsource_GENTOO
- https://www.cve.org/CVERecord?id=CVE-2014-0107
- https://www.oracle.com//security-alerts/cpujul2021.html x_refsource_MISC
- https://www.oracle.com/security-alerts/cpuoct2021.html x_refsource_MISC
- https://www.oracle.com/technetwork/security-advisory/cpuapr2019-5072813.html x_refsource_MISC
- https://www.tenable.com/security/tns-2018-15 x_refsource_CONFIRM
Change history (0)
No recorded changes yet.