CVE-2014-0107
Apache Xalan-Java could allow a remote attacker to bypass security restrictions, caused by the improper handling of output properties. An attacker could exploit this vulnerability to bypass the secure processing feature to load arbitrary restricted classes.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the vulnerability in Apache Xalan-Java?
The vulnerability in Apache Xalan-Java is CVE-2014-0107.
How does CVE-2014-0107 impact Apache Xalan-Java?
CVE-2014-0107 can allow a remote attacker to bypass security restrictions and load arbitrary classes or access external resources.
What is the severity of CVE-2014-0107?
The severity of CVE-2014-0107 is high with a CVSS score of 7.
How can I fix the vulnerability in Apache Xalan-Java CVE-2014-0107?
To fix CVE-2014-0107, update your Apache Xalan-Java installation to version 2.7.2 or above.
Where can I find more information about CVE-2014-0107?
You can find more information about CVE-2014-0107 in the following references: [Link 1](https://issues.apache.org/jira/browse/XALANJ-2435), [Link 2](http://svn.apache.org/viewvc?view=revision&revision=1581058), [Link 3](http://www.ocert.org/advisories/ocert-2014-002.html).