AUGUST 4, 2026
Live Feed
Return to register
Case File

CVE-2014-0096

MEDIUM · CVSS 4.3 EPSS 6.91%

Source: NVD + CISA KEV + EPSS (historical backfill) · Published 2014-05-31 · Last synced 2026-08-04

Field Assessment

AI analysis pending.

CVE
CVE-2014-0096
Severity
MEDIUM
CVSS
4.3
EPSS
6.91%
Apache Java

Original Filing — NVD Description

java/org/apache/catalina/servlets/DefaultServlet.java in the default servlet in Apache Tomcat before 6.0.40, 7.x before 7.0.53, and 8.x before 8.0.4 does not properly restrict XSLT stylesheets, which allows remote attackers to bypass security-manager restrictions and read arbitrary files via a crafted web application that provides an XML external entity declaration in conjunction with an entity reference, related to an XML External Entity (XXE) issue.