JVNDB-2014-002143
|
Apache Xalan-Java �� TransformerFactory �ɂ�������҂�����������������Ǝ㐫
|
Apache Xalan-Java �� TransformerFactory �́AFEATURE_SECURE_PROCESSING ���L���ȏꍇ�A����̃v���p�e�B��K�ɐ������Ȃ����߁A���҂����������������A�C�ӂ̃N���X�����[�h�����A�܂��͊O�����\�[�X�ɃA�N�Z�X�����Ǝ㐫�����݂��܂��B
|
CVSS v2 �ɂ��[���x ��{�l: 7.5 (�댯) [NVD�l]
- �U�����敪: �l�b�g���[�N
- �U�������̕��G��: ��
- �U���O�̔F�ؗv��: �s�v
- �@�����ւ̉e��(C): �����I
- ���S���ւ̉e��(I): �����I
- �p���ւ̉e��(A): �����I
|
|
Apache Software Foundation
IBM
- IBM Security QRadar SIEM 7.1 MR2
- IBM Security QRadar SIEM 7.2 MR2
- IBM Sterling B2B Integrator 5.1
- IBM Sterling Control Center 5.2.01 ���� 5.2.11
- IBM Sterling File Gateway 2.1
�I���N��
- Oracle Fusion Middleware �� Oracle WebCenter Sites 11.1.1.8.0
- Oracle Fusion Middleware �� Oracle WebCenter Sites 7.6.2
- Oracle Fusion Middleware �� Oracle WebLogic Server 10.3.6
- Oracle Fusion Middleware �� Oracle WebLogic Server 12.1.2
- Oracle Fusion Middleware �� Oracle WebLogic Server 12.1.3
����
- Cosminexus XML Processor
- Hitachi Infrastructure Analytics Advisor
- uCosminexus Application Server -R
- uCosminexus Application Server Express
- uCosminexus Application Server Light
- uCosminexus Application Server Enterprise
- uCosminexus Application Server Smart Edition
- uCosminexus Application Server Standard
- uCosminexus Application Server Standard -R
- uCosminexus Client
- uCosminexus Client for Plug-in
- uCosminexus Developer 01
- uCosminexus Developer Professional
- uCosminexus Developer Professional for Plug-in
- uCosminexus Developer Light
- uCosminexus Developer Standard
- uCosminexus Operator
- uCosminexus Primary Server Base
- uCosminexus Server Standard-R
- uCosminexus Service Architect
- uCosminexus Service Platform
- uCosminexus Service Platform - Messaging
|
�{�Ǝ㐫�̉e�����鐻�i�̏ڍׂɂ��ẮA�x���_�������m�F���������B
|
��O�҂ɂ��A�I���ɍH���ꂽ�ȉ��̃v���p�e�B�A�܂��� XSLT 1.0 �� system-property ���Ƀo�C���h���ꂽ Java �v���p�e�B����āA���҂����������������A�C�ӂ̃N���X�����[�h�����A�܂��͊O�����\�[�X�ɃA�N�Z�X�����\��������܂��B
(1) xalan:content-header �v���p�e�B
(2) xalan:entities �v���p�e�B
(3) xslt:content-header �v���p�e�B
(4) xslt:entities �v���p�e�B
|
�x���_��萳���ȑ��J����Ă��܂��B�x���_�����Q�Ƃ��ēK�ȑ�����{���Ă��������B
|
Apache Software Foundation
IBM
�I���N��
���b�h�n�b�g
����
|
- �F�E�����E�A�N�Z�X����(CWE-264) [NVD�]��]
|
- CVE-2014-0107
|
- National Vulnerability Database (NVD) : CVE-2014-0107
- �֘A���� : #2014-002 Xalan-Java insufficient secure processing
|
- [2014�N04��21��]
�f��
[2014�N08��06��]
�e������V�X�e���F�x���_���̒lj��ɔ������e���X�V
�x���_���FIBM (1677145) ��lj�
[2014�N09��09��]
�e������V�X�e���F�x���_���̒lj��ɔ������e���X�V
�x���_���FIBM (1681933) ��lj�
�x���_���FIBM (1680703) ��lj�
[2014�N10��30��]
�x���_���F���b�h�n�b�g (RHSA-2014:1351) ��lj�
[2016�N01��28��]
�e������V�X�e���F�x���_���̒lj��ɔ������e���X�V
�x���_���F�I���N�� (Oracle Critical Patch Update Advisory - January 2016) ��lj�
�x���_���F�I���N�� (Text Form of Oracle Critical Patch Update - January 2016 Risk Matrices) ��lj�
�x���_���F�I���N�� (January 2016 Critical Patch Update Released) ��lj�
[2017�N05��16��]
�e������V�X�e���F�x���_���̒lj��ɔ������e���X�V
�x���_���F���� (hitachi-sec-2017-113) ��lj�
- [2019�N04��16��]
�e������V�X�e���F�x���_���̒lj��ɔ������e���X�V
�x���_���F���� (hitachi-sec-2019-108) ��lj�
|