CVE-2015-0254
Vulnerability Summary
Timeline
Description
Apache Standard Taglibs before 1.2.3 allows remote attackers to execute arbitrary code or conduct external XML entity (XXE) attacks via a crafted XSLT extension in a (1) <x:parse> or (2) <x:transform> JSTL XML tag.
CVSS Metrics
- v3.0•HIGH•Score: 7.6CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:H/A:L
- v2.0•HIGH•Score: 7.5AV:N/AC:L/Au:N/C:P/I:P/A:P
EPSS Trends
Current EPSS score: 13.26%• Percentile: 96%
Affected Systems
- apache•standard_taglibs
≤ 1.2.1
- canonical•ubuntu_linux
14.04 | 14.10
- org.apache.taglibs•taglibs-standard
< 1.2.3
- org.apache.taglibs•taglibs-standard-impl
< 1.2.3
- redhat•apache-cxf
< 0:2.7.18-1.redhat_1.1.ep6.el5 | < 0:2.7.18-1.redhat_1.1.ep6.el6 | < 0:2.7.18-1.redhat_1.1.ep6.el7
- redhat•hibernate4-core-eap6
< 0:4.2.22-1.Final_redhat_1.1.ep6.el5 | < 0:4.2.22-1.Final_redhat_1.1.ep6.el6 | < 0:4.2.22-1.Final_redhat_1.1.ep6.el7
- redhat•hibernate4-eap6
< 0:4.2.22-1.Final_redhat_1.1.ep6.el5 | < 0:4.2.22-1.Final_redhat_1.1.ep6.el6 | < 0:4.2.22-1.Final_redhat_1.1.ep6.el7
- redhat•hibernate4-entitymanager-eap6
< 0:4.2.22-1.Final_redhat_1.1.ep6.el5 | < 0:4.2.22-1.Final_redhat_1.1.ep6.el6 | < 0:4.2.22-1.Final_redhat_1.1.ep6.el7
- redhat•hibernate4-envers-eap6
< 0:4.2.22-1.Final_redhat_1.1.ep6.el5 | < 0:4.2.22-1.Final_redhat_1.1.ep6.el6 | < 0:4.2.22-1.Final_redhat_1.1.ep6.el7
- redhat•hibernate4-infinispan-eap6
< 0:4.2.22-1.Final_redhat_1.1.ep6.el5 | < 0:4.2.22-1.Final_redhat_1.1.ep6.el6 | < 0:4.2.22-1.Final_redhat_1.1.ep6.el7
- redhat•hibernate4-validator
< 0:4.3.2-3.Final_redhat_3.1.ep6.el5 | < 0:4.3.2-3.Final_redhat_3.1.ep6.el6 | < 0:4.3.2-3.Final_redhat_3.1.ep6.el7
- redhat•hornetq
< 0:2.3.25-10.SP8_redhat_1.1.ep6.el5 | < 0:2.3.25-10.SP8_redhat_1.1.ep6.el6 | < 0:2.3.25-10.SP8_redhat_1.1.ep6.el7
- redhat•httpserver
< 0:1.0.6-1.Final_redhat_1.1.ep6.el5 | < 0:1.0.6-1.Final_redhat_1.1.ep6.el6 | < 0:1.0.6-1.Final_redhat_1.1.ep6.el7
- redhat•infinispan
< 0:5.2.17-1.Final_redhat_1.1.ep6.el5 | < 0:5.2.17-1.Final_redhat_1.1.ep6.el6 | < 0:5.2.17-1.Final_redhat_1.1.ep6.el7
- redhat•infinispan-cachestore-jdbc
< 0:5.2.17-1.Final_redhat_1.1.ep6.el5 | < 0:5.2.17-1.Final_redhat_1.1.ep6.el6 | < 0:5.2.17-1.Final_redhat_1.1.ep6.el7
- redhat•infinispan-cachestore-remote
< 0:5.2.17-1.Final_redhat_1.1.ep6.el5 | < 0:5.2.17-1.Final_redhat_1.1.ep6.el6 | < 0:5.2.17-1.Final_redhat_1.1.ep6.el7
- redhat•infinispan-client-hotrod
< 0:5.2.17-1.Final_redhat_1.1.ep6.el5 | < 0:5.2.17-1.Final_redhat_1.1.ep6.el6 | < 0:5.2.17-1.Final_redhat_1.1.ep6.el7
- redhat•infinispan-core
< 0:5.2.17-1.Final_redhat_1.1.ep6.el5 | < 0:5.2.17-1.Final_redhat_1.1.ep6.el6 | < 0:5.2.17-1.Final_redhat_1.1.ep6.el7
- redhat•ironjacamar-common-api-eap6
< 0:1.0.35-1.Final_redhat_1.1.ep6.el5 | < 0:1.0.35-1.Final_redhat_1.1.ep6.el6 | < 0:1.0.35-1.Final_redhat_1.1.ep6.el7
- redhat•ironjacamar-common-impl-eap6
< 0:1.0.35-1.Final_redhat_1.1.ep6.el5 | < 0:1.0.35-1.Final_redhat_1.1.ep6.el6 | < 0:1.0.35-1.Final_redhat_1.1.ep6.el7
- redhat•ironjacamar-common-spi-eap6
< 0:1.0.35-1.Final_redhat_1.1.ep6.el5 | < 0:1.0.35-1.Final_redhat_1.1.ep6.el6 | < 0:1.0.35-1.Final_redhat_1.1.ep6.el7
- redhat•ironjacamar-core-api-eap6
< 0:1.0.35-1.Final_redhat_1.1.ep6.el5 | < 0:1.0.35-1.Final_redhat_1.1.ep6.el6 | < 0:1.0.35-1.Final_redhat_1.1.ep6.el7
- redhat•ironjacamar-core-impl-eap6
< 0:1.0.35-1.Final_redhat_1.1.ep6.el5 | < 0:1.0.35-1.Final_redhat_1.1.ep6.el6 | < 0:1.0.35-1.Final_redhat_1.1.ep6.el7
- redhat•ironjacamar-deployers-common-eap6
< 0:1.0.35-1.Final_redhat_1.1.ep6.el5 | < 0:1.0.35-1.Final_redhat_1.1.ep6.el6 | < 0:1.0.35-1.Final_redhat_1.1.ep6.el7
- redhat•ironjacamar-eap6
< 0:1.0.35-1.Final_redhat_1.1.ep6.el5 | < 0:1.0.35-1.Final_redhat_1.1.ep6.el6 | < 0:1.0.35-1.Final_redhat_1.1.ep6.el7
- redhat•ironjacamar-jdbc-eap6
< 0:1.0.35-1.Final_redhat_1.1.ep6.el5 | < 0:1.0.35-1.Final_redhat_1.1.ep6.el6 | < 0:1.0.35-1.Final_redhat_1.1.ep6.el7
- redhat•ironjacamar-spec-api-eap6
< 0:1.0.35-1.Final_redhat_1.1.ep6.el5 | < 0:1.0.35-1.Final_redhat_1.1.ep6.el6 | < 0:1.0.35-1.Final_redhat_1.1.ep6.el7
- redhat•ironjacamar-validator-eap6
< 0:1.0.35-1.Final_redhat_1.1.ep6.el5 | < 0:1.0.35-1.Final_redhat_1.1.ep6.el6 | < 0:1.0.35-1.Final_redhat_1.1.ep6.el7
- redhat•jakarta-taglibs-standard
< 0:1.1.1-11.7.el6_7 | < 0:1.1.1-11.7.el6_7 | < 0:1.1.1-11.7.el6_7 | < 0:1.1.1-11.7.el6_7 | < 0:1.1.2-14.el7_1 | < 0:1.1.2-14.el7_1 | < 0:1.1.2-14.el7_1 | < 0:1.1.2-14.el7_1
- redhat•jakarta-taglibs-standard-javadoc
< 0:1.1.1-11.7.el6_7 | < 0:1.1.1-11.7.el6_7 | < 0:1.1.1-11.7.el6_7 | < 0:1.1.1-11.7.el6_7 | < 0:1.1.2-14.el7_1 | < 0:1.1.2-14.el7_1 | < 0:1.1.2-14.ael7b_1 | < 0:1.1.2-14.el7_1
- redhat•jboss-as-appclient
< 0:7.5.6-1.Final_redhat_2.1.ep6.el5 | < 0:7.5.6-1.Final_redhat_2.1.ep6.el6 | < 0:7.5.6-1.Final_redhat_2.1.ep6.el7
- redhat•jboss-as-cli
< 0:7.5.6-1.Final_redhat_2.1.ep6.el5 | < 0:7.5.6-1.Final_redhat_2.1.ep6.el6 | < 0:7.5.6-1.Final_redhat_2.1.ep6.el7
- redhat•jboss-as-client-all
< 0:7.5.6-1.Final_redhat_2.1.ep6.el5 | < 0:7.5.6-1.Final_redhat_2.1.ep6.el6 | < 0:7.5.6-1.Final_redhat_2.1.ep6.el7
- redhat•jboss-as-clustering
< 0:7.5.6-1.Final_redhat_2.1.ep6.el5 | < 0:7.5.6-1.Final_redhat_2.1.ep6.el6 | < 0:7.5.6-1.Final_redhat_2.1.ep6.el7
- redhat•jboss-as-cmp
< 0:7.5.6-1.Final_redhat_2.1.ep6.el5 | < 0:7.5.6-1.Final_redhat_2.1.ep6.el6 | < 0:7.5.6-1.Final_redhat_2.1.ep6.el7
- redhat•jboss-as-configadmin
< 0:7.5.6-1.Final_redhat_2.1.ep6.el5 | < 0:7.5.6-1.Final_redhat_2.1.ep6.el6 | < 0:7.5.6-1.Final_redhat_2.1.ep6.el7
- redhat•jboss-as-connector
< 0:7.5.6-1.Final_redhat_2.1.ep6.el5 | < 0:7.5.6-1.Final_redhat_2.1.ep6.el6 | < 0:7.5.6-1.Final_redhat_2.1.ep6.el7
- redhat•jboss-as-controller
< 0:7.5.6-1.Final_redhat_2.1.ep6.el5 | < 0:7.5.6-1.Final_redhat_2.1.ep6.el6 | < 0:7.5.6-1.Final_redhat_2.1.ep6.el7
- redhat•jboss-as-controller-client
< 0:7.5.6-1.Final_redhat_2.1.ep6.el5 | < 0:7.5.6-1.Final_redhat_2.1.ep6.el6 | < 0:7.5.6-1.Final_redhat_2.1.ep6.el7
- redhat•jboss-as-core-security
< 0:7.5.6-1.Final_redhat_2.1.ep6.el5 | < 0:7.5.6-1.Final_redhat_2.1.ep6.el6 | < 0:7.5.6-1.Final_redhat_2.1.ep6.el7
- redhat•jboss-as-deployment-repository
< 0:7.5.6-1.Final_redhat_2.1.ep6.el5 | < 0:7.5.6-1.Final_redhat_2.1.ep6.el6 | < 0:7.5.6-1.Final_redhat_2.1.ep6.el7
- redhat•jboss-as-deployment-scanner
< 0:7.5.6-1.Final_redhat_2.1.ep6.el5 | < 0:7.5.6-1.Final_redhat_2.1.ep6.el6 | < 0:7.5.6-1.Final_redhat_2.1.ep6.el7
- redhat•jboss-as-domain-http
< 0:7.5.6-1.Final_redhat_2.1.ep6.el5 | < 0:7.5.6-1.Final_redhat_2.1.ep6.el6 | < 0:7.5.6-1.Final_redhat_2.1.ep6.el7
- redhat•jboss-as-domain-management
< 0:7.5.6-1.Final_redhat_2.1.ep6.el5 | < 0:7.5.6-1.Final_redhat_2.1.ep6.el6 | < 0:7.5.6-1.Final_redhat_2.1.ep6.el7
- redhat•jboss-as-ee
< 0:7.5.6-1.Final_redhat_2.1.ep6.el5 | < 0:7.5.6-1.Final_redhat_2.1.ep6.el6 | < 0:7.5.6-1.Final_redhat_2.1.ep6.el7
- redhat•jboss-as-ee-deployment
< 0:7.5.6-1.Final_redhat_2.1.ep6.el5 | < 0:7.5.6-1.Final_redhat_2.1.ep6.el6 | < 0:7.5.6-1.Final_redhat_2.1.ep6.el7
- redhat•jboss-as-ejb3
< 0:7.5.6-1.Final_redhat_2.1.ep6.el5 | < 0:7.5.6-1.Final_redhat_2.1.ep6.el6 | < 0:7.5.6-1.Final_redhat_2.1.ep6.el7
- redhat•jboss-as-embedded
< 0:7.5.6-1.Final_redhat_2.1.ep6.el5 | < 0:7.5.6-1.Final_redhat_2.1.ep6.el6 | < 0:7.5.6-1.Final_redhat_2.1.ep6.el7
- redhat•jboss-as-host-controller
< 0:7.5.6-1.Final_redhat_2.1.ep6.el5 | < 0:7.5.6-1.Final_redhat_2.1.ep6.el6 | < 0:7.5.6-1.Final_redhat_2.1.ep6.el7
- redhat•jboss-as-jacorb
< 0:7.5.6-1.Final_redhat_2.1.ep6.el5 | < 0:7.5.6-1.Final_redhat_2.1.ep6.el6 | < 0:7.5.6-1.Final_redhat_2.1.ep6.el7
Showing first 50 affected entries in server-rendered view.
References (86)
- http://www.ubuntu.com/usn/USN-2551-1
- https://access.redhat.com/errata/RHSA-2016:1376
- http://rhn.redhat.com/errata/RHSA-2016-1841.html
- http://mail-archives.apache.org/mod_mbox/tomcat-taglibs-user/201502.mbox/%3C82207A16-6348-4DEE-877E-F7B87292576A%40apache.org%3E
- http://rhn.redhat.com/errata/RHSA-2016-1838.html
- http://www.securityfocus.com/archive/1/534772/100/0/threaded
- http://rhn.redhat.com/errata/RHSA-2015-1695.html
- http://rhn.redhat.com/errata/RHSA-2016-1839.html
- http://lists.opensuse.org/opensuse-updates/2015-10/msg00033.html
- http://www.securityfocus.com/bid/72809
- http://rhn.redhat.com/errata/RHSA-2016-1840.html
- http://www.securitytracker.com/id/1034934
- https://lists.apache.org/thread.html/8a20e48acb2a40be5130df91cf9d39d8ad93181989413d4abcaa4914%40%3Cdev.tomcat.apache.org%3E
- https://lists.apache.org/thread.html/f8e0814e11c7f21f42224b6de111cb3f5e5ab5c15b78924c516d4ec2%40%3Cdev.tomcat.apache.org%3E
- https://lists.apache.org/thread.html/rfc2bfd99c340dafd501676693cd889c1f9f838b97bdd0776a8f5557d%40%3Cdev.tomcat.apache.org%3E
- https://lists.apache.org/thread.html/re3b72cbb13e1dfe85c4a06959a3b6ca6d939b407ecca80db12b54220%40%3Cdev.tomcat.apache.org%3E
- https://www.oracle.com/security-alerts/cpuapr2020.html
- http://www.oracle.com/technetwork/security-advisory/cpujul2017-3236622.html
- https://lists.apache.org/thread.html/rc1686f6196bb9063bf26577a21b8033c19c1a30e5a9159869c8f3d38%40%3Cpluto-dev.portals.apache.org%3E
- https://lists.apache.org/thread.html/rf1179e6971bc46f0f68879a9a10cc97ad4424451b0889aeef04c8077%40%3Cpluto-scm.portals.apache.org%3E
- https://lists.apache.org/thread.html/r6c93d8ade3788dbc00f5a37238bc278e7d859f2446b885460783a16f%40%3Cpluto-dev.portals.apache.org%3E
- https://www.oracle.com//security-alerts/cpujul2021.html
- http://packetstormsecurity.com/files/130575/Apache-Standard-Taglibs-1.2.1-XXE-Remote-Command-Execution.html
- https://nvd.nist.gov/vuln/detail/CVE-2015-0254
- https://lists.apache.org/thread.html/8a20e48acb2a40be5130df91cf9d39d8ad93181989413d4abcaa4914@%3Cdev.tomcat.apache.org%3E
- https://lists.apache.org/thread.html/f8e0814e11c7f21f42224b6de111cb3f5e5ab5c15b78924c516d4ec2@%3Cdev.tomcat.apache.org%3E
- https://lists.apache.org/thread.html/r6c93d8ade3788dbc00f5a37238bc278e7d859f2446b885460783a16f@%3Cpluto-dev.portals.apache.org%3E
- https://lists.apache.org/thread.html/rc1686f6196bb9063bf26577a21b8033c19c1a30e5a9159869c8f3d38@%3Cpluto-dev.portals.apache.org%3E
- https://lists.apache.org/thread.html/re3b72cbb13e1dfe85c4a06959a3b6ca6d939b407ecca80db12b54220@%3Cdev.tomcat.apache.org%3E
- https://lists.apache.org/thread.html/rf1179e6971bc46f0f68879a9a10cc97ad4424451b0889aeef04c8077@%3Cpluto-scm.portals.apache.org%3E
- https://lists.apache.org/thread.html/rfc2bfd99c340dafd501676693cd889c1f9f838b97bdd0776a8f5557d@%3Cdev.tomcat.apache.org%3E
- https://access.redhat.com/errata/RHSA-2015:1695
- https://access.redhat.com/security/updates/classification/#important
- https://access.redhat.com/solutions/1584363
- https://bugzilla.redhat.com/show_bug.cgi?id=1198606
- https://security.access.redhat.com/data/csaf/v2/advisories/2015/rhsa-2015_1695.json
- https://access.redhat.com/security/cve/CVE-2015-0254
- https://www.cve.org/CVERecord?id=CVE-2015-0254
- https://access.redhat.com/errata/RHSA-2016:0121
- https://access.redhat.com/documentation/en-US/JBoss_Enterprise_Application_Platform/6.4/index.html
- https://bugzilla.redhat.com/show_bug.cgi?id=1275693
- https://bugzilla.redhat.com/show_bug.cgi?id=1286739
- https://bugzilla.redhat.com/show_bug.cgi?id=1286837
- https://bugzilla.redhat.com/show_bug.cgi?id=1289296
- https://bugzilla.redhat.com/show_bug.cgi?id=1289299
- https://bugzilla.redhat.com/show_bug.cgi?id=1289305
- https://bugzilla.redhat.com/show_bug.cgi?id=1289625
- https://bugzilla.redhat.com/show_bug.cgi?id=1289749
- https://bugzilla.redhat.com/show_bug.cgi?id=1290034
- https://bugzilla.redhat.com/show_bug.cgi?id=1290060
- https://bugzilla.redhat.com/show_bug.cgi?id=1290813
- https://bugzilla.redhat.com/show_bug.cgi?id=1290818
- https://bugzilla.redhat.com/show_bug.cgi?id=1298277
- https://security.access.redhat.com/data/csaf/v2/advisories/2016/rhsa-2016_0121.json
- https://access.redhat.com/errata/RHSA-2016:0122
- https://bugzilla.redhat.com/show_bug.cgi?id=1275692
- https://bugzilla.redhat.com/show_bug.cgi?id=1286738
- https://bugzilla.redhat.com/show_bug.cgi?id=1286836
- https://bugzilla.redhat.com/show_bug.cgi?id=1289295
- https://bugzilla.redhat.com/show_bug.cgi?id=1289298
- https://bugzilla.redhat.com/show_bug.cgi?id=1289304
- https://bugzilla.redhat.com/show_bug.cgi?id=1289624
- https://bugzilla.redhat.com/show_bug.cgi?id=1289748
- https://bugzilla.redhat.com/show_bug.cgi?id=1290033
- https://bugzilla.redhat.com/show_bug.cgi?id=1290059
- https://bugzilla.redhat.com/show_bug.cgi?id=1290812
- https://bugzilla.redhat.com/show_bug.cgi?id=1290817
- https://bugzilla.redhat.com/show_bug.cgi?id=1298276
- https://security.access.redhat.com/data/csaf/v2/advisories/2016/rhsa-2016_0122.json
- https://access.redhat.com/errata/RHSA-2016:0123
- https://bugzilla.redhat.com/show_bug.cgi?id=1275694
- https://bugzilla.redhat.com/show_bug.cgi?id=1286740
- https://bugzilla.redhat.com/show_bug.cgi?id=1286838
- https://bugzilla.redhat.com/show_bug.cgi?id=1289297
- https://bugzilla.redhat.com/show_bug.cgi?id=1289300
- https://bugzilla.redhat.com/show_bug.cgi?id=1289306
- https://bugzilla.redhat.com/show_bug.cgi?id=1289626
- https://bugzilla.redhat.com/show_bug.cgi?id=1289750
- https://bugzilla.redhat.com/show_bug.cgi?id=1290035
- https://bugzilla.redhat.com/show_bug.cgi?id=1290061
- https://bugzilla.redhat.com/show_bug.cgi?id=1290814
- https://bugzilla.redhat.com/show_bug.cgi?id=1290819
- https://bugzilla.redhat.com/show_bug.cgi?id=1298278
- https://security.access.redhat.com/data/csaf/v2/advisories/2016/rhsa-2016_0123.json
- https://access.redhat.com/errata/RHSA-2016:0124
- https://security.access.redhat.com/data/csaf/v2/advisories/2016/rhsa-2016_0124.json