CVE-2014-0002
Camel: XML eXternal Entity (XXE) flaw in XSLT component
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
1Exploited in Wild
-Decision
Descriptions
The XSLT component in Apache Camel before 2.11.4 and 2.12.x before 2.12.3 allows remote attackers to read arbitrary files and possibly have other unspecified impact via an XML document containing an external entity declaration in conjunction with an entity reference, related to an XML External Entity (XXE) issue.
El componente XSLT en Apache Camel anterior a 2.11.4 y 2.12.x anterior a 2.12.3 permite a atacantes remotos leer archivos arbitrarios y posiblemente tener otro impacto no especificado a través de un documento XML que contiene una declaración de entidad externa en conjunción con una referencia de entidad, relacionado con un problema de XML External Entity (XXE).
Red Hat JBoss Fuse Service Works is the next-generation ESB and business process automation infrastructure. Red Hat JBoss Fuse Service Works allows IT to leverage existing, modern, and future integration methodologies to dramatically improve business process execution speed and quality. This roll up patch serves as a cumulative upgrade for Red Hat JBoss Fuse Service Works 6.0.0. It includes various bug fixes, which are listed in the README file included with the patch files.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2013-12-03 CVE Reserved
- 2014-03-02 CVE Published
- 2024-08-06 CVE Updated
- 2024-08-06 First Exploit
- 2025-04-15 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
CWE
- CWE-264: Permissions, Privileges, and Access Controls
- CWE-611: Improper Restriction of XML External Entity Reference
CAPEC
References (11)
URL | Tag | Source |
---|---|---|
http://secunia.com/advisories/57716 | Third Party Advisory | |
http://secunia.com/advisories/57719 | Third Party Advisory | |
http://www.securityfocus.com/bid/65901 | Vdb Entry | |
https://lists.apache.org/thread.html/2318d7f7d87724d8716cd650c21b31cb06e4d34f6d0f5ee42f28fdaf%40%3Ccommits.camel.apache.org%3E | Mailing List | |
https://lists.apache.org/thread.html/b4014ea7c5830ca1fc28edd5cafedfe93ad4af2d9e69c961c5def31d%40%3Ccommits.camel.apache.org%3E | Mailing List |
URL | Date | SRC |
---|---|---|
http://camel.apache.org/security-advisories.data/CVE-2014-0002.txt.asc | 2024-08-06 |
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
http://rhn.redhat.com/errata/RHSA-2014-0371.html | 2023-02-13 | |
http://rhn.redhat.com/errata/RHSA-2014-0372.html | 2023-02-13 | |
http://secunia.com/advisories/57125 | 2023-02-13 | |
https://access.redhat.com/security/cve/CVE-2014-0002 | 2014-04-30 | |
https://bugzilla.redhat.com/show_bug.cgi?id=1049675 | 2014-04-30 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Apache Search vendor "Apache" | Camel Search vendor "Apache" for product "Camel" | <= 2.11.3 Search vendor "Apache" for product "Camel" and version " <= 2.11.3" | - |
Affected
| ||||||
Apache Search vendor "Apache" | Camel Search vendor "Apache" for product "Camel" | 1.0.0 Search vendor "Apache" for product "Camel" and version "1.0.0" | - |
Affected
| ||||||
Apache Search vendor "Apache" | Camel Search vendor "Apache" for product "Camel" | 1.1.0 Search vendor "Apache" for product "Camel" and version "1.1.0" | - |
Affected
| ||||||
Apache Search vendor "Apache" | Camel Search vendor "Apache" for product "Camel" | 1.2.0 Search vendor "Apache" for product "Camel" and version "1.2.0" | - |
Affected
| ||||||
Apache Search vendor "Apache" | Camel Search vendor "Apache" for product "Camel" | 1.3.0 Search vendor "Apache" for product "Camel" and version "1.3.0" | - |
Affected
| ||||||
Apache Search vendor "Apache" | Camel Search vendor "Apache" for product "Camel" | 1.4.0 Search vendor "Apache" for product "Camel" and version "1.4.0" | - |
Affected
| ||||||
Apache Search vendor "Apache" | Camel Search vendor "Apache" for product "Camel" | 1.5.0 Search vendor "Apache" for product "Camel" and version "1.5.0" | - |
Affected
| ||||||
Apache Search vendor "Apache" | Camel Search vendor "Apache" for product "Camel" | 1.6.0 Search vendor "Apache" for product "Camel" and version "1.6.0" | - |
Affected
| ||||||
Apache Search vendor "Apache" | Camel Search vendor "Apache" for product "Camel" | 1.6.1 Search vendor "Apache" for product "Camel" and version "1.6.1" | - |
Affected
| ||||||
Apache Search vendor "Apache" | Camel Search vendor "Apache" for product "Camel" | 1.6.2 Search vendor "Apache" for product "Camel" and version "1.6.2" | - |
Affected
| ||||||
Apache Search vendor "Apache" | Camel Search vendor "Apache" for product "Camel" | 1.6.3 Search vendor "Apache" for product "Camel" and version "1.6.3" | - |
Affected
| ||||||
Apache Search vendor "Apache" | Camel Search vendor "Apache" for product "Camel" | 1.6.4 Search vendor "Apache" for product "Camel" and version "1.6.4" | - |
Affected
| ||||||
Apache Search vendor "Apache" | Camel Search vendor "Apache" for product "Camel" | 2.0.0 Search vendor "Apache" for product "Camel" and version "2.0.0" | - |
Affected
| ||||||
Apache Search vendor "Apache" | Camel Search vendor "Apache" for product "Camel" | 2.0.0 Search vendor "Apache" for product "Camel" and version "2.0.0" | milestone1 |
Affected
| ||||||
Apache Search vendor "Apache" | Camel Search vendor "Apache" for product "Camel" | 2.0.0 Search vendor "Apache" for product "Camel" and version "2.0.0" | milestone2 |
Affected
| ||||||
Apache Search vendor "Apache" | Camel Search vendor "Apache" for product "Camel" | 2.0.0 Search vendor "Apache" for product "Camel" and version "2.0.0" | milestone3 |
Affected
| ||||||
Apache Search vendor "Apache" | Camel Search vendor "Apache" for product "Camel" | 2.1.0 Search vendor "Apache" for product "Camel" and version "2.1.0" | - |
Affected
| ||||||
Apache Search vendor "Apache" | Camel Search vendor "Apache" for product "Camel" | 2.10.0 Search vendor "Apache" for product "Camel" and version "2.10.0" | - |
Affected
| ||||||
Apache Search vendor "Apache" | Camel Search vendor "Apache" for product "Camel" | 2.10.1 Search vendor "Apache" for product "Camel" and version "2.10.1" | - |
Affected
| ||||||
Apache Search vendor "Apache" | Camel Search vendor "Apache" for product "Camel" | 2.10.2 Search vendor "Apache" for product "Camel" and version "2.10.2" | - |
Affected
| ||||||
Apache Search vendor "Apache" | Camel Search vendor "Apache" for product "Camel" | 2.10.3 Search vendor "Apache" for product "Camel" and version "2.10.3" | - |
Affected
| ||||||
Apache Search vendor "Apache" | Camel Search vendor "Apache" for product "Camel" | 2.10.4 Search vendor "Apache" for product "Camel" and version "2.10.4" | - |
Affected
| ||||||
Apache Search vendor "Apache" | Camel Search vendor "Apache" for product "Camel" | 2.10.5 Search vendor "Apache" for product "Camel" and version "2.10.5" | - |
Affected
| ||||||
Apache Search vendor "Apache" | Camel Search vendor "Apache" for product "Camel" | 2.10.6 Search vendor "Apache" for product "Camel" and version "2.10.6" | - |
Affected
| ||||||
Apache Search vendor "Apache" | Camel Search vendor "Apache" for product "Camel" | 2.10.7 Search vendor "Apache" for product "Camel" and version "2.10.7" | - |
Affected
| ||||||
Apache Search vendor "Apache" | Camel Search vendor "Apache" for product "Camel" | 2.11.0 Search vendor "Apache" for product "Camel" and version "2.11.0" | - |
Affected
| ||||||
Apache Search vendor "Apache" | Camel Search vendor "Apache" for product "Camel" | 2.11.1 Search vendor "Apache" for product "Camel" and version "2.11.1" | - |
Affected
| ||||||
Apache Search vendor "Apache" | Camel Search vendor "Apache" for product "Camel" | 2.11.2 Search vendor "Apache" for product "Camel" and version "2.11.2" | - |
Affected
| ||||||
Apache Search vendor "Apache" | Camel Search vendor "Apache" for product "Camel" | 2.12.0 Search vendor "Apache" for product "Camel" and version "2.12.0" | - |
Affected
| ||||||
Apache Search vendor "Apache" | Camel Search vendor "Apache" for product "Camel" | 2.12.1 Search vendor "Apache" for product "Camel" and version "2.12.1" | - |
Affected
| ||||||
Apache Search vendor "Apache" | Camel Search vendor "Apache" for product "Camel" | 2.12.2 Search vendor "Apache" for product "Camel" and version "2.12.2" | - |
Affected
|