CVE-2014-8111
mod_jk: information leak due to incorrect JkMount/JkUnmount directives processing
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
Apache Tomcat Connectors (mod_jk) before 1.2.41 ignores JkUnmount rules for subtrees of previous JkMount rules, which allows remote attackers to access otherwise restricted artifacts via unspecified vectors.
Apache Tomcat Connectors (mod_jk) anterior a 1.2.41 ignora las reglas JkUnmount para los sunárboles de anteriores reglas JkMount, lo que permite a atacantes remotos acceder a artefactos de otra forma restringidos a través de vectores no especificados.
It was discovered that a JkUnmount rule for a subtree of a previous JkMount rule could be ignored. This could allow a remote attacker to potentially access a private artifact in a tree that would otherwise not be accessible to them.
Red Hat JBoss Enterprise Application Platform 6 is a platform for Java applications based on JBoss Application Server 7. It was found that a prior countermeasure in Apache WSS4J for Bleichenbacher's attack on XML Encryption threw an exception that permitted an attacker to determine the failure of the attempted attack, thereby leaving WSS4J vulnerable to the attack. The original flaw allowed a remote attacker to recover the entire plain text form of a symmetric key. It was found that Apache WSS4J permitted bypass of the requireSignedEncryptedDataElements configuration property via XML Signature wrapping attacks. A remote attacker could use this flaw to modify the contents of a signed request.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2014-10-10 CVE Reserved
- 2015-04-17 CVE Published
- 2024-08-06 CVE Updated
- 2025-04-03 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-200: Exposure of Sensitive Information to an Unauthorized Actor
CAPEC
References (16)
URL | Date | SRC |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
http://rhn.redhat.com/errata/RHSA-2015-0846.html | 2023-11-07 | |
http://rhn.redhat.com/errata/RHSA-2015-0847.html | 2023-11-07 | |
http://rhn.redhat.com/errata/RHSA-2015-0848.html | 2023-11-07 | |
http://rhn.redhat.com/errata/RHSA-2015-0849.html | 2023-11-07 | |
http://rhn.redhat.com/errata/RHSA-2015-1641.html | 2023-11-07 | |
http://rhn.redhat.com/errata/RHSA-2015-1642.html | 2023-11-07 | |
http://www.debian.org/security/2015/dsa-3278 | 2023-11-07 | |
https://access.redhat.com/security/cve/CVE-2014-8111 | 2015-08-18 | |
https://bugzilla.redhat.com/show_bug.cgi?id=1182591 | 2015-08-18 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Apache Search vendor "Apache" | Tomcat Connectors Search vendor "Apache" for product "Tomcat Connectors" | <= 1.2.40 Search vendor "Apache" for product "Tomcat Connectors" and version " <= 1.2.40" | - |
Affected
|