Oval Definition:oval:org.mitre.oval:def:26183
Revision Date:2014-10-13Version:8
Title:RHSA-2014:1034: tomcat security update (Low)
Description:Apache Tomcat is a servlet container for the Java Servlet and JavaServerPages (JSP) technologies.It was found that, in certain circumstances, it was possible for amalicious web application to replace the XML parsers used by Apache Tomcatto process XSLTs for the default servlet, JSP documents, tag librarydescriptors (TLDs), and tag plug-in configuration files. The injected XMLparser(s) could then bypass the limits imposed on XML external entitiesand/or gain access to the XML files processed for other web applicationsdeployed on the same Apache Tomcat instance. (CVE-2014-0119)All Tomcat users are advised to upgrade to these updated packages, whichcontain a backported patch to correct this issue. Tomcat must be restartedfor this update to take effect.
Family:unixClass:patch
Status:ACCEPTEDReference(s):CESA-2014:1034
CVE-2014-0119
RHSA-2014:1034-00
Platform(s):CentOS Linux 7
Red Hat Enterprise Linux 7
Product(s):tomcat
Definition Synopsis
  • Redhat 7 or Centos 7 release
  • The operating system installed on the system is Red Hat Enterprise Linux 7
  • OR The operating system installed on the system is CentOS Linux 7.x
  • AND Packages section
  • tomcat is earlier than 0:7.0.42-8.el7_0
  • OR tomcat-admin-webapps is earlier than 0:7.0.42-8.el7_0
  • OR tomcat-docs-webapp is earlier than 0:7.0.42-8.el7_0
  • OR tomcat-el-2.2-api is earlier than 0:7.0.42-8.el7_0
  • OR tomcat-javadoc is earlier than 0:7.0.42-8.el7_0
  • OR tomcat-jsp-2.2-api is earlier than 0:7.0.42-8.el7_0
  • OR tomcat-jsvc is earlier than 0:7.0.42-8.el7_0
  • OR tomcat-lib is earlier than 0:7.0.42-8.el7_0
  • OR tomcat-servlet-3.0-api is earlier than 0:7.0.42-8.el7_0
  • OR tomcat-webapps is earlier than 0:7.0.42-8.el7_0
  • BACK