Apache Tomcat CVE-2014-0119 XML External Entity Information Disclosure Vulnerability

Bugtraq ID: 67669
Class: Design Error
CVE: CVE-2014-0119
Remote: Yes
Local: No
Published: May 27 2014 12:00AM
Updated: Oct 26 2016 12:10AM
Credit: Tomcat security team
Vulnerable: Ubuntu Ubuntu Linux 15.04
Ubuntu Ubuntu Linux 14.10
Ubuntu Ubuntu Linux 14.04 LTS
Redhat JBoss Enterprise Application Platform 6.2 EL6
Redhat JBoss Enterprise Application Platform 6.2 EL5
Redhat JBoss Enterprise Application Platform 6 EL6
Redhat JBoss Enterprise Application Platform 6 EL5
Redhat Enterprise Linux Workstation Optional 6
Redhat Enterprise Linux Workstation 6
Redhat Enterprise Linux Server Optional 6
Redhat Enterprise Linux Server 6
Redhat Enterprise Linux HPC Node Optional 6
Redhat Enterprise Linux Desktop Optional 6
Oracle Enterprise Linux 7
Oracle Enterprise Linux 6.2
Oracle Enterprise Linux 6
Oracle Enterprise Data Quality 9.0.11
Oracle Enterprise Data Quality 8.1.2
Oracle Communications Policy Management 12.1.1
Oracle Communications Policy Management 10.4.1
Oracle Communications Policy Management 9.9.1
Oracle Communications Policy Management 9.7.3
Mandriva Business Server 1 X86 64
Mandriva Business Server 1
Juniper Security Threat Response Manager 2013.2
Juniper Security Threat Response Manager 2013.1
Juniper Security Threat Response Manager 2012.1
Juniper Secure Analytics 2014.2
Juniper Secure Analytics 2014.1
Juniper Secure Analytics 2013.2
IBM WebSphere Application Server Community Edition 3.0.0.4
IBM WebSphere Application Server Community Edition 2.1.1.6
IBM UrbanCode Release 6.0.1
IBM UrbanCode Release 6.0.1.4
IBM UrbanCode Release 6.0.1.3
IBM UrbanCode Release 6.0.1.2
IBM UrbanCode Release 6.0.1.1
IBM UrbanCode Release 6.0.0.1
IBM UrbanCode Release 6.0
IBM UrbanCode Deploy 6.0.1 4
IBM UrbanCode Deploy 6.0.1 3
IBM UrbanCode Deploy 6.0.1 2
IBM UrbanCode Deploy 6.0.1 1
IBM UrbanCode Deploy 6.0.1
IBM UrbanCode Deploy 6.1.0.2
IBM UrbanCode Deploy 6.1.0.1
IBM UrbanCode Deploy 6.1
IBM UrbanCode Deploy 6.0.1.5
IBM UrbanCode Deploy 6.0
IBM Tivoli Application Dependency Discovery Manager 7.2.2
IBM Tivoli Application Dependency Discovery Manager 7.2.1
IBM Tivoli Application Dependency Discovery Manager 7.2.0
IBM Tivoli Application Dependency Discovery Manager 7.1.2
IBM Security AppScan Enterprise 9.0
IBM Security AppScan Enterprise 8.8
IBM Security AppScan Enterprise 8.7
IBM Security AppScan Enterprise 8.6
IBM Scale Out Network Attached Storage 1.3.2 1-21
IBM Scale Out Network Attached Storage 1.3.2 1-20
IBM Scale Out Network Attached Storage 1.3.2
IBM Scale Out Network Attached Storage 1.3.1
IBM Scale Out Network Attached Storage 1.4.3.3
IBM Scale Out Network Attached Storage 1.4.3.2
IBM Scale Out Network Attached Storage 1.4.3.1
IBM Scale Out Network Attached Storage 1.4.3.0
IBM Scale Out Network Attached Storage 1.4.2.1
IBM Scale Out Network Attached Storage 1.4.2.0
IBM Scale Out Network Attached Storage 1.4.1.0
IBM Scale Out Network Attached Storage 1.3.2.3
IBM Scale Out Network Attached Storage 1.3.2.2
IBM Scale Out Network Attached Storage 1.3.0.5
IBM Scale Out Network Attached Storage 1.3.0.4
IBM Scale Out Network Attached Storage 1.3.0.0
IBM Rational Test Workbench 8.5 2
IBM Rational Test Workbench 8.5 1
IBM Rational Test Workbench 8.0.1 4
IBM Rational Test Workbench 8.0.1 3
IBM Rational Test Workbench 8.0.1 2
IBM Rational Test Workbench 8.0.1 1
IBM Rational Test Workbench 8.0.1
IBM Rational Test Workbench 8.0 3
IBM Rational Test Workbench 8.0 2
IBM Rational Test Workbench 8.0 1
IBM Rational Test Workbench 8.5
IBM Rational Test Workbench 8.0
IBM Rational Test Virtualization Server 8.0
IBM Rational Test Virtualization Server 8.5.0.0
IBM Rational SAP Connector 4.0.0.4
IBM Rational SAP Connector 4.0.0.3
IBM Rational SAP Connector 4.0.0.2
IBM Rational SAP Connector 4.0.0.1
IBM Rational Policy Tester 8.5
IBM Rational Lifecycle Adapter for HP ALM 1.1
IBM Rational Lifecycle Adapter for HP ALM 1.0
IBM Rational DOORS Web Access 9.5.2 1
IBM Rational DOORS Web Access 9.5.2
IBM Rational DOORS Web Access 9.5.1 1
IBM Rational DOORS Web Access 9.5.1
IBM Rational DOORS Web Access 9.5 1
IBM Rational DOORS Web Access 1.5 1
IBM Rational DOORS Web Access 1.4 5
IBM Rational DOORS Web Access 1.4 4
IBM Rational DOORS Web Access 9.6
IBM Rational DOORS Web Access 9.5
IBM Rational DOORS Web Access 1.5
IBM Rational Directory Server 5.2.1
IBM Rational Directory Server 6.0.0.1
IBM Rational Directory Server 6.0
IBM Rational Directory Server 5.2.0.2
IBM Rational Directory Server 5.2.0.1
IBM Rational Directory Server 5.2
IBM Rational Directory Server 5.1.1.2
IBM Rational Directory Server 5.1.1.1
IBM Rational Directory Server 5.1.1
IBM QRadar Security Information and Event Manager 7.2
IBM QRadar Security Information and Event Manager 7.1
IBM Power HMC 8.2.0.0
IBM Power HMC 8.1.0.0
IBM Power HMC 7.7.9.0
IBM Power HMC 7.7.8.0
IBM Power HMC 7.7.3.0
IBM OpenPages GRC Platform 7.0
IBM OpenPages GRC Platform 6.2.1
IBM OpenPages GRC Platform 6.1.0.1
IBM OpenPages GRC Platform 6.0.1.5
IBM Guardium Database Activity Monitor 9.1
IBM Guardium Database Activity Monitor 9.0
IBM Cognos Metrics Manager 10.2.1
IBM Cognos Metrics Manager 10.2
IBM Cognos Metrics Manager 10.1.1
IBM Cognos Metrics Manager 10.1
IBM Cognos Business Viewpoint 10.1.1 FP2
IBM Cognos Business Viewpoint 10.1.1 FP1
IBM Cognos Business Viewpoint 10.1 FP1
IBM Cognos Business Intelligence Server 10.2.1 1
IBM Cognos Business Intelligence Server 10.2.1
IBM Cognos Business Intelligence Server 10.1.1
IBM Cognos Business Intelligence Server 10.2
IBM Cognos Business Intelligence Server 10.1
IBM Algo Audit and Compliance 2.1.0.2
IBM Algo Audit and Compliance 2.1
HP OpenVMS CSWS_JAVA 7.0.29
HP HP-UX B.11.31
Gentoo Linux
F5 Enterprise Manager 3.1.1
F5 Enterprise Manager 3.1
F5 Enterprise Manager 3.0
F5 Enterprise Manager 2.3
F5 Enterprise Manager 2.1
F5 BIG-IP WOM 11.2
F5 BIG-IP WOM 11.0
F5 BIG-IP WOM 10.2.4
F5 BIG-IP WOM 10.2.2
F5 BIG-IP WOM 10.2.1
F5 BIG-IP WOM 10.0
F5 BIG-IP WOM 11.3.0
F5 BIG-IP WOM 11.2.1
F5 BIG-IP WOM 11.1.0
F5 BIG-IP WebAccelerator 11.2.0 0
F5 BIG-IP WebAccelerator 11.3
F5 BIG-IP WebAccelerator 11.2.1
F5 BIG-IP WebAccelerator 11.1
F5 BIG-IP WebAccelerator 11.0
F5 BIG-IP WebAccelerator 10.2.4
F5 BIG-IP WebAccelerator 10.2.1
F5 BIG-IP WebAccelerator 10.0
F5 BIG-IP PSM 11.4.1
F5 BIG-IP PSM 11.3
F5 BIG-IP PSM 11.2
F5 BIG-IP PSM 11.1
F5 BIG-IP PSM 11.0
F5 BIG-IP PSM 10.2.4
F5 BIG-IP PSM 10.2.1
F5 BIG-IP PSM 10.0
F5 BIG-IP PSM 11.2.1
F5 BIG-IP PEM 11.5.1
F5 BIG-IP PEM 11.5
F5 BIG-IP PEM 11.3
F5 BIG-IP PEM 11.4.1
F5 BIG-IP LTM 11.5.1
F5 BIG-IP LTM 11.5
F5 BIG-IP LTM 11.2
F5 BIG-IP LTM 11.0
F5 BIG-IP LTM 10.2.4
F5 BIG-IP LTM 10.2.2
F5 BIG-IP LTM 10.0
F5 BIG-IP LTM 11.4.1
F5 BIG-IP LTM 11.3.0
F5 BIG-IP LTM 11.2.1
F5 BIG-IP LTM 11.1.0
F5 BIG-IP LTM 10.2.1
F5 BIG-IP Link Controller 11.2.0 0
F5 BIG-IP Link Controller 11.5.1
F5 BIG-IP Link Controller 11.5
F5 BIG-IP Link Controller 11.3
F5 BIG-IP Link Controller 11.2.1
F5 BIG-IP Link Controller 11.1
F5 BIG-IP Link Controller 11.0
F5 BIG-IP Link Controller 10.2.4
F5 BIG-IP Link Controller 10.2.2
F5 BIG-IP Link Controller 10.2.1
F5 BIG-IP Link Controller 10.0
F5 BIG-IP Link Controller 11.4.1
F5 BIG-IP GTM 11.5.1
F5 BIG-IP GTM 11.5
F5 BIG-IP GTM 11.3
F5 BIG-IP GTM 11.2
F5 BIG-IP GTM 11.0
F5 BIG-IP GTM 10.2.4
F5 BIG-IP GTM 10.2.2
F5 BIG-IP GTM 10.2.1
F5 BIG-IP GTM 10.0
F5 BIG-IP GTM 11.4.1
F5 BIG-IP GTM 11.2.1
F5 BIG-IP GTM 11.1.0
F5 BIG-IP Edge Gateway 11.3
F5 BIG-IP Edge Gateway 11.2.1
F5 BIG-IP Edge Gateway 11.2
F5 BIG-IP Edge Gateway 11.1
F5 BIG-IP Edge Gateway 11.0
F5 BIG-IP Edge Gateway 10.2.4
F5 BIG-IP Edge Gateway 10.2.2
F5 BIG-IP Edge Gateway 10.2.1
F5 BIG-IP Edge Gateway 10.1
F5 BIG-IP ASM 11.2.0 0
F5 BIG-IP ASM 11.0.0 0
F5 BIG-IP ASM 10.2.4 0
F5 BIG-IP ASM 10.0.0 0
F5 BIG-IP ASM 11.5.1
F5 BIG-IP ASM 11.5
F5 BIG-IP ASM 10.2.2
F5 BIG-IP ASM 10.2.1
F5 BIG-IP ASM 11.4.1
F5 BIG-IP ASM 11.3.0
F5 BIG-IP ASM 11.2.1
F5 BIG-IP ASM 11.1.0
F5 BIG-IP APM 11.5.1
F5 BIG-IP APM 11.2
F5 BIG-IP APM 11.0
F5 BIG-IP APM 10.2.4
F5 BIG-IP APM 10.2.2
F5 BIG-IP APM 11.5.0
F5 BIG-IP APM 11.4.1
F5 BIG-IP APM 11.4.0
F5 BIG-IP APM 11.3.0
F5 BIG-IP APM 11.2.1
F5 BIG-IP APM 11.1.0
F5 BIG-IP APM 10.2.1
F5 BIG-IP APM 10.1
F5 BIG-IP Analytics 11.5.1
F5 BIG-IP Analytics 11.5
F5 BIG-IP Analytics 11.3
F5 BIG-IP Analytics 11.2.1
F5 BIG-IP Analytics 11.2
F5 BIG-IP Analytics 11.4.1
F5 BIG-IP Analytics 11.1.0
F5 BIG-IP Analytics 11.0.0
F5 BIG-IP AFM 11.5.1
F5 BIG-IP AFM 11.5
F5 BIG-IP AFM 11.3
F5 BIG-IP AFM 11.4.1
F5 BIG-IP AAM 11.5.1
F5 BIG-IP AAM 11.5
F5 BIG-IP AAM 11.4.1
F5 BIG-IP AAM 11.4.0
F5 ARX 6.4
F5 ARX 6.3
F5 ARX 6.2
F5 ARX 6.1.1
F5 ARX 6.1
F5 ARX 6.0
Debian Linux 6.0 sparc
Debian Linux 6.0 s/390
Debian Linux 6.0 powerpc
Debian Linux 6.0 mips
Debian Linux 6.0 ia-64
Debian Linux 6.0 ia-32
Debian Linux 6.0 arm
Debian Linux 6.0 amd64
CentOS CentOS 6
Avaya Proactive Contact 5.1
Avaya Proactive Contact 5.0
Avaya Proactive Contact 4.2.2
Avaya Proactive Contact 4.2.1
Avaya Proactive Contact 4.2
Avaya Messaging Application Server 5.2.1
Avaya Messaging Application Server 5.0.1
Avaya Messaging Application Server 5.2
Avaya Messaging Application Server 5.0
Avaya Meeting Exchange 6.2
Avaya Meeting Exchange 6.0
Avaya IQ 4.1
Avaya IQ 5.2
Avaya IQ 5.1.1
Avaya IQ 5.1
Avaya IQ 5
Avaya IQ 4.2
Avaya IQ 4.0
Avaya IP Office Server Edition 9.0
Avaya IP Office Server Edition 8.1
Avaya IP Office Server Edition 8.0
Avaya IP Office Application Server 9.0 SP 2
Avaya IP Office Application Server 9.0 SP 1
Avaya IP Office Application Server 9.0
Avaya IP Office Application Server 8.1
Avaya IP Office Application Server 8.0
Avaya Conferencing Standard Edition 6.0.1
Avaya Conferencing Standard Edition 6.0 SP1
Avaya Communication Server 1000M Signaling Server 7.6
Avaya Communication Server 1000M Signaling Server 7.5
Avaya Communication Server 1000M Signaling Server 7.0
Avaya Communication Server 1000M Signaling Server 6.0
Avaya Communication Server 1000M Signaling Server 5.5
Avaya Communication Server 1000M 7.6
Avaya Communication Server 1000M 7.5
Avaya Communication Server 1000M 7.0
Avaya Communication Server 1000M 6.0
Avaya Communication Server 1000M 5.5
Avaya Communication Server 1000E Signaling Server 7.6
Avaya Communication Server 1000E Signaling Server 7.5
Avaya Communication Server 1000E Signaling Server 7.0
Avaya Communication Server 1000E Signaling Server 6.0
Avaya Communication Server 1000E Signaling Server 5.5
Avaya Communication Server 1000E 7.6
Avaya Communication Server 1000E 7.5
Avaya Communication Server 1000E 7.0
Avaya Communication Server 1000E 6.0
Avaya Communication Server 1000E 5.5
Avaya Aura Utility Services 6.3
Avaya Aura Utility Services 6.2
Avaya Aura System Platform 6.2.2
Avaya Aura System Platform 6.2.1
Avaya Aura System Platform 6.0.2
Avaya Aura System Platform 6.0.1
Avaya Aura System Platform 6.3
Avaya Aura System Platform 6.2.1.0.9
Avaya Aura System Platform 6.2 SP1
Avaya Aura System Platform 6.2
Avaya Aura System Platform 6.0.3.9.3
Avaya Aura System Platform 6.0.3.8.3
Avaya Aura System Platform 6.0.3.0.3
Avaya Aura System Platform 6.0 SP3
Avaya Aura System Platform 6.0 SP2
Avaya Aura System Platform 6.0
Avaya Aura System Platform 1.1
Avaya Aura Presence Services 6.1.1
Avaya Aura Presence Services 6.1 SP2
Avaya Aura Presence Services 6.1 SP1
Avaya Aura Presence Services 6.1
Avaya Aura Presence Services 6.0
Avaya Aura Messaging 6.1.1
Avaya Aura Messaging 6.3
Avaya Aura Messaging 6.2 SP4
Avaya Aura Messaging 6.2
Avaya Aura Messaging 6.1
+ Avaya Communication Manager Server DEFINITY Server SI/CS
+ Avaya Communication Manager Server S8100
+ Avaya Communication Manager Server S8300
+ Avaya Communication Manager Server S8500
+ Avaya Communication Manager Server S8700
Avaya Aura Messaging 6.0.1
Avaya Aura Messaging 6.0
Avaya Aura Experience Portal 6.0.2
+ Avaya Communication Manager Server DEFINITY Server SI/CS
+ Avaya Communication Manager Server S8100
+ Avaya Communication Manager Server S8300
+ Avaya Communication Manager Server S8500
+ Avaya Communication Manager Server S8700
Avaya Aura Experience Portal 6.0.1
Avaya Aura Experience Portal 7.0
Avaya Aura Experience Portal 6.0 SP2
+ Avaya Communication Manager Server DEFINITY Server SI/CS
+ Avaya Communication Manager Server S8100
+ Avaya Communication Manager Server S8300
+ Avaya Communication Manager Server S8500
+ Avaya Communication Manager Server S8700
Avaya Aura Experience Portal 6.0 SP1
Avaya Aura Experience Portal 6.0
Avaya Aura Conferencing 6.0 Standard
Avaya Aura Conferencing 6.0 SP1 Standard
Avaya Aura Application Server 5300 SIP Core 3.0 PB5
Avaya Aura Application Server 5300 SIP Core 3.0 PB3
Avaya Aura Application Server 5300 SIP Core 3.0
Avaya Aura Application Server 5300 SIP Core 2.1
Avaya Aura Application Server 5300 SIP Core 2.0 PB28
Avaya Aura Application Server 5300 SIP Core 2.0 PB26
Avaya Aura Application Server 5300 SIP Core 2.0 PB25
Avaya Aura Application Server 5300 SIP Core 2.0 PB23
Avaya Aura Application Server 5300 SIP Core 2.0 PB19
Avaya Aura Application Server 5300 SIP Core 2.0 PB16
Avaya Aura Application Server 5300 SIP Core 2.0
Avaya Aura Application Enablement Services 6.3
Avaya Aura Application Enablement Services 6.2
Avaya Aura Application Enablement Services 6.1.2
Avaya Aura Application Enablement Services 6.1.1
Avaya Aura Application Enablement Services 6.1
Avaya Aura Application Enablement Services 6.0
Apache Tomcat 8.0.5
Apache Tomcat 8.0.3
Apache Tomcat 8.0.1
Apache Tomcat 7.0.53
Apache Tomcat 7.0.50
Apache Tomcat 7.0.33
Apache Tomcat 7.0.32
Apache Tomcat 7.0.31
Apache Tomcat 7.0.30
Apache Tomcat 7.0.29
Apache Tomcat 7.0.28
Apache Tomcat 7.0.27
Apache Tomcat 7.0.26
Apache Tomcat 7.0.25
Apache Tomcat 7.0.24
Apache Tomcat 7.0.23
Apache Tomcat 7.0.16
Apache Tomcat 7.0.15
Apache Tomcat 7.0.14
Apache Tomcat 7.0.13
Apache Tomcat 7.0.12
Apache Tomcat 7.0.9
Apache Tomcat 7.0.8
Apache Tomcat 7.0.7
Apache Tomcat 7.0.6
Apache Tomcat 7.0.4
Apache Tomcat 7.0.3
Apache Tomcat 7.0.2
Apache Tomcat 7.0.1
Apache Tomcat 7.0 beta
Apache Tomcat 7.0
Apache Tomcat 6.0.37
Apache Tomcat 6.0.36
Apache Tomcat 6.0.35
Apache Tomcat 6.0.28
Apache Tomcat 6.0.27
Apache Tomcat 6.0.26
Apache Tomcat 6.0.25
Apache Tomcat 6.0.24
Apache Tomcat 6.0.20
Apache Tomcat 6.0.18
Apache Tomcat 6.0.17
Apache Tomcat 6.0.16
Apache Tomcat 6.0.15
Apache Tomcat 6.0.14
Apache Tomcat 6.0.13
Apache Tomcat 6.0.12
Apache Tomcat 6.0.11
Apache Tomcat 6.0.10
Apache Tomcat 6.0.9
Apache Tomcat 6.0.8
Apache Tomcat 6.0.7
Apache Tomcat 6.0.6
Apache Tomcat 6.0.5
Apache Tomcat 6.0.4
Apache Tomcat 6.0.3
Apache Tomcat 6.0.2
Apache Tomcat 6.0.1
Apache Tomcat 6.0
Apache Tomcat 8.0.0-RC6
Apache Tomcat 8.0.0-RC5
Apache Tomcat 8.0.0-RC3
Apache Tomcat 8.0.0-RC10
Apache Tomcat 8.0.0-RC1
Apache Tomcat 8.0.0 Rc5
Apache Tomcat 8.0.0 Rc2
Apache Tomcat 8.0.0 Rc10
Apache Tomcat 8.0.0 Rc1
Apache Tomcat 7.0.5
Apache Tomcat 7.0.49
Apache Tomcat 7.0.48
Apache Tomcat 7.0.47
Apache Tomcat 7.0.46
Apache Tomcat 7.0.45
Apache Tomcat 7.0.44
Apache Tomcat 7.0.43
Apache Tomcat 7.0.42
Apache Tomcat 7.0.41
Apache Tomcat 7.0.40
Apache Tomcat 7.0.4 Beta
Apache Tomcat 7.0.39
Apache Tomcat 7.0.38
Apache Tomcat 7.0.37
Apache Tomcat 7.0.36
Apache Tomcat 7.0.35
Apache Tomcat 7.0.34
Apache Tomcat 7.0.22
Apache Tomcat 7.0.21
Apache Tomcat 7.0.20
Apache Tomcat 7.0.2 Beta
Apache Tomcat 7.0.19
Apache Tomcat 7.0.18
Apache Tomcat 7.0.11
Apache Tomcat 7.0.10
Apache Tomcat 6.0.39
Apache Tomcat 6.0.33
Apache Tomcat 6.0.32
Apache Tomcat 6.0.31
Apache Tomcat 6.0.30
Apache Tomcat 6.0.29
Apache Tomcat 6.0.19
Not Vulnerable: Juniper Security Threat Response Manager 2013.2R9
Juniper Secure Analytics 2014.3R1
Juniper Secure Analytics 2013.2R9
IBM Tivoli Application Dependency Discovery Manager 7.2.2.1
IBM Tivoli Application Dependency Discovery Manager 7.2.1.6
IBM Tivoli Application Dependency Discovery Manager 7.2.0.10
IBM Scale Out Network Attached Storage 1.4.3.4
IBM Rational SAP Connector 4.0.0.5
IBM OpenPages GRC Platform 6.1.0.1.4
Apache Tomcat 8.0.8
Apache Tomcat 7.0.54
Apache Tomcat 6.0.41


 

Privacy Statement
Copyright 2010, SecurityFocus