IBM disclosed that Apache Tomcat components bundled with Rational Lifecycle Adapter for HP ALM 1.0–1.1 and IBM UrbanCode Release 6.0–6.0.1.4 and 6.1 expose remotely exploitable vulnerabilities without authentication. The issues include denial of service, HTTP request smuggling, session fixation, and information disclosure; deployments of Rational Lifecycle Adapter using WebSphere Application Server are not affected.
Of particular concern, CVE-2014-0096 and CVE-2014-0119 are XXE-related flaws that permit crafted web applications to read arbitrary files, including files belonging to other applications on the same Tomcat host in the latter case. Organizations should update UrbanCode Release 6.1 to 6.1.0.1 or later and apply 6.0.1.4.ifix01 to the 6.0 line; affected Tomcat installations should be upgraded to fixed releases, including 6.0.40, 7.0.54, and 8.0.6 or later as applicable.

See real exploitation activity before you spend the cycle.
7 events from the most recent confirmed update back to the earliest known activity.
IBM published a bulletin stating that UrbanCode Release versions 6.0 through 6.0.1.4 and 6.1 contained vulnerable Apache Tomcat components, including CVE-2014-0096 and CVE-2014-0119. IBM advised upgrading the 6.1 line to 6.1.0.1 or later and installing 6.0.1.4.ifix01 for the 6.0 line.
CVE-2014-0119 was published as an XXE information-disclosure vulnerability involving the class loader's XML parser access for XSLT stylesheets. A crafted web application could read arbitrary files, including files associated with other applications on the same Tomcat instance; fixes were included in 6.0.40, 7.0.54, and 8.0.6.
CVE-2014-0096 was published as an XXE-related information-disclosure flaw in Tomcat's default servlet. Crafted web applications could bypass Security Manager restrictions and read arbitrary files; Tomcat 6.0.40, 7.0.53, and 8.0.4 addressed the affected version lines.
Red Hat released a Moderate-impact Apache Tomcat 7 update for Red Hat JBoss Web Server 2.0.1, addressing CVE-2014-0075, CVE-2014-0099, and CVE-2014-0096. Users were advised to install the update and restart the JBoss Web Server process.
Apache Tomcat's requestedSessionSSL field was not reset when a Request object was recycled, potentially allowing control of a subsequent session ID and contributing to session fixation under uncommon SSL-session-ID application configurations. Apache committed fixes for Tomcat 7 and 8, and Red Hat issued updates for affected JBoss Web Server, JBoss Enterprise Web Server, and Red Hat Enterprise Linux products.
Apache Tomcat was found vulnerable to XXE attacks when resolving external entities in application-supplied XML files, allowing a malicious deployed web application to expose Tomcat internals and bypass Java Security Manager restrictions. Upstream fixed the issue in Tomcat 6.0.39, 7.0.50, and 8.0.0-RC10; Red Hat issued fixes for several products but declined to fix Tomcat 5 in RHEL 5 due to compatibility risks during reduced support.
IBM reported that Rational Lifecycle Adapter for HP ALM versions 1.0 through 1.1 were affected by multiple Apache Tomcat vulnerabilities, including CVE-2014-0096 and CVE-2014-0119. Deployments using WebSphere Application Server were stated to be unaffected.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See real exploitation activity behind this advisory so you can triage it against everything else in the queue.
7 references tracked. Mallory keeps watching after this page renders.
cve.mitre.org
Open sourcerhn.redhat.com
Open sourcecve.mitre.org
Open sourcebugzilla.redhat.com
Open sourcewww-01.ibm.com
Open sourcebugzilla.redhat.com
Open sourcewww-01.ibm.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.