CVE-2014-0107 affects Xalan-Java's XSLT secure-processing feature: insufficient restrictions on specified properties and features let an attacker supplying malicious XSLT bypass intended processing safeguards. Where suitable components are available on the application classpath, exploitation can lead to arbitrary remote code execution in the application server context. Red Hat rated the flaw Important, with a CVSS v2 score of 6.8, and issued fixes for affected Red Hat Enterprise Linux, JBoss, and Fuse products.
Red Hat also included the Xalan-Java issue in RHSA-2015:1888 for JBoss SOA Platform 5.3.1, alongside certificate hostname-validation, XML deserialization, XXE, and authentication-related flaws. Organizations running affected JBoss deployments should apply the vendor update after backing up installations and stopping the JBoss Application Server; the vulnerability reflects an improperly implemented required security check, allowing secure-processing controls to be circumvented.

See affected versions and whether adversaries are exploiting it.
10 events from the most recent confirmed update back to the earliest known activity.
Red Hat issued Important-severity advisory RHSA-2015:1888 for JBoss SOA Platform 5.3.1, fixing seven CVEs including CVE-2014-0107. The update also addressed hostname-validation, XML deserialization, authentication logging, and XXE flaws, and Red Hat advised customers to apply it.
Red Hat issued RHSA-2014:1369 to fix CVE-2014-0107 in Fuse ESB Enterprise, Fuse Management Console, and Fuse MQ Enterprise version 7.1.0.
Red Hat released RHSA-2014:1351 for Red Hat JBoss A-MQ 6.1, addressing CVE-2014-0107.
Red Hat issued RHSA-2014:1291 to fix CVE-2014-0107 in the xalan-j2 component of Red Hat JBoss BPMS 6.0.
Red Hat issued RHSA-2014:1007 to remediate CVE-2014-0107 in the xalan-j2 component of JBoss Enterprise BRMS Platform 5.3.
Red Hat released RHSA-2014:0819 for JBoss BPMS 6.0 and RHSA-2014:0818 for JBoss BRMS 6.0, addressing the Xalan-Java secure-processing vulnerability CVE-2014-0107.
Red Hat issued RHSA-2014:0348 to fix CVE-2014-0107 in the xalan-j2 component of Red Hat Enterprise Linux 5 and 6. The flaw allowed supplied XSLT to bypass Xalan-Java secure-processing restrictions and could enable remote code execution depending on the application classpath.
Fedora pushed xstream-1.3.1-9.fc20 to the Fedora 20 stable repository and xstream-1.3.1-5.1.fc19 to the Fedora 19 stable repository, addressing CVE-2013-7285 insecure XML deserialization and potential remote code execution.
Red Hat published CVE-2013-7285, an Important XStream insecure-deserialization vulnerability. An attacker able to supply XML to an XStream application could deserialize arbitrary object types and potentially execute code in the server's security context.
Apache Xalan-J was reported to allow XSLT output properties to remain effective despite FEATURE_SECURE_PROCESSING. Attacker-controlled stylesheets could specify content-handler classes for arbitrary class loading or entities resources that could exhaust memory.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See whether adversaries are exploiting this yet, and where the affected versions run in your environment.
10 references tracked. Mallory keeps watching after this page renders.
rhn.redhat.com
Open sourceaccess.redhat.com
Open sourceredhat.com
Open sourceredhat.com
Open sourceocert.org
Open sourcecwe.mitre.org
Open sourceissues.apache.org
Open sourcecwe.mitre.org
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.