CVE-2015-0254

Description

Apache Standard Taglibs before 1.2.3 allows remote attackers to execute arbitrary code or conduct external XML entity (XXE) attacks via a crafted XSLT extension in a (1) or (2) JSTL XML tag.

Risk Information

Base Score
7.6
MODERATE
Vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:H/A:L
EPSS Score
Exploitation Probability
3.808

Associated Vulnerability

VulnerabilityOS Platform
Multiple vulnerabilities are affected in Oracle WebLogic Server 10.3.6.0.0Windows
Multiple vulnerabilities are affected in Oracle WebLogic Server 12.1.3.0.0Windows
Multiple vulnerabilities are fixed in IBM WebSphere 7.0.0.43Windows
Multiple vulnerabilities are fixed in IBM WebSphere 8.0.0.13Windows
Multiple vulnerabilities are fixed in IBM WebSphere 8.5.5.10Windows
Vulnerabilities CVE-2015-0254 are fixed in Apache-taglibs-standard 1.2.3Windows
Vulnerabilities CVE-2015-0254 are fixed in Apache-taglibs-standard-impl 1.2.3Windows
Multiple Vulnerabilities are affected in IBM Tivoli Monitoring 6.3.0Windows
Multiple Vulnerabilities are affected in IBM Sterling B2B Integrator 6.1.0.3Windows
Multiple Vulnerabilities are affected in IBM Sterling B2B Integrator 6.0.3.4Windows
Implementation of JSP Standard Tag Library (JSTL) (USN-2551-1) libjstl1.1-java_1.1.2-2ubuntu1.14.04.1_all.debLinux
Implementation of JSP Standard Tag Library (JSTL) (USN-2551-1) libjakarta-taglibs-standard-java_1.1.2-2ubuntu1.14.04.1_all.debLinux
(RHSA-2015:1695) Important: jakarta-taglibs-standard security update jakarta-taglibs-standard-1.1.1-11.7.el6_7.noarch.rpmLinux
(RHSA-2015:1695) Important: jakarta-taglibs-standard security update jakarta-taglibs-standard-javadoc-1.1.1-11.7.el6_7.noarch.rpmLinux
SUSE-SU-2017:1568-1(SUSE Linux Enterprise Server 12-SP2 ) jakarta-taglibs-standard-1.1.1-255.2.noarch.rpmLinux
SUSE-SU-2017:1568-1(SUSE Linux Enterprise Server 12-SP2 ) jakarta-taglibs-standard-javadoc-1.1.1-255.2.noarch.rpmLinux
SUSE-SU-2017:1701-1(SUSE Linux Enterprise Server 11-SP4 ) jakarta-taglibs-standard-1.1.1-234.31.1.noarch.rpmLinux
SUSE-SU-2017:1701-1(SUSE Linux Enterprise Server 11-SP4 ) jakarta-taglibs-standard-javadoc-1.1.1-234.31.1.noarch.rpmLinux
Jakarta-taglibs-standard update (ELSA-2015-1695) jakarta-taglibs-standard-1.1.2-14.el7_1.noarch.rpmLinux
Jakarta-taglibs-standard-javadoc update (ELSA-2015-1695) jakarta-taglibs-standard-javadoc-1.1.2-14.el7_1.noarch.rpmLinux
(RHSA-2015:1695)Important: security update jakarta-taglibs-standard-1.1.2-14.el7_1.noarch.rpmLinux
(RHSA-2015:1695)Important: security update jakarta-taglibs-standard-javadoc-1.1.2-14.el7_1.noarch.rpmLinux
Vulnerabilities CVE-2015-0254 are fixed in Apache-taglibs-standard for Linux 1.2.3Linux
Vulnerabilities CVE-2015-0254 are fixed in Apache-taglibs-standard-impl for Linux 1.2.3Linux

Patch Details

No records found

References

https://nvd.nist.gov/vuln/detail/CVE-2023-1234
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1234