CVE-2014-1972

Apache Tapestry before 5.3.6 relies on client-side object storage without checking whether a client has modified an object, which allows remote attackers to cause a denial of service (resource consumption) or execute arbitrary code via crafted serialized data.

Published: 2015-08-22 Last update: 2026-05-06 Assigner: [email protected] Source: [email protected]

Conclusion & alert: CVE-2014-1972 is rated High Risk (65.2/100): CVSS High severity, with high exploitation likelihood (EPSS 9.60%, 95th percentile). Core evidence: EPSS ranks this CVE among the most likely to be exploited in the near term. Mandatory action: High exploitation likelihood—assess exposure and prioritize remediation.

Risk is dynamic; we continuously reassess and refresh what is shown on this page as upstream context changes.

Exploit prediction scoring system (EPSS) score for CVE-2014-1972

EPSS lead: Daily EPSS estimates relative likelihood of exploitation; percentile ranks this CVE among scored vulnerabilities (higher = more severe relative rank).

# Date Old EPSS score New EPSS score Delta (New - Old)
1 2026-06-15 8.82% 9.60% +0.78%
2 2026-03-17 8.87% 8.82% -0.05%
3 2026-01-28 8.87%

Full EPSS history (12 records total)

Common vulnerability scoring system (CVSS) metrics for CVE-2014-1972

CVSS metrics for this CVE.

Base score Version Severity Vector Exploitability Impact Score source
7.8 2.0 HIGH
AV:N/AC:L/Au:N/C:N/I:N/A:C Click to expand
Access vector (AV:N)
Can be exploited remotely over network reachability.
Access complexity (AC:L)
Exploitation conditions are straightforward and predictable.
Authentication (AU:N)
No authentication is required.
Confidentiality impact (C:N)
No confidentiality impact.
Integrity impact (I:N)
No integrity impact.
Availability impact (A:C)
Complete availability impact.
10.0 6.9 [email protected]

Weakness enumeration for CVE-2014-1972

GitHub Security Advisory for CVE-2014-1972

GHSA-c438-8cvq-pxxx · Severity: high · Ecosystem: maven — Apache Tapestry Unsafe Object Storage

Affected software / configurations for CVE-2014-1972

Vendor Product Version Raw CPE
apache tapestry <= 5.3.5 cpe:2.3:a:apache:tapestry:*:*:*:*:*:*:*:*

References for CVE-2014-1972

URL Tags
http://jvn.jp/en/jp/JVN17611367/index.html Vendor Advisory
http://jvndb.jvn.jp/jvndb/JVNDB-2015-000118 Vendor Advisory
http://seclists.org/fulldisclosure/2019/Aug/20
http://www.openwall.com/lists/oss-security/2019/08/23/5
https://issues.apache.org/jira/browse/TAP5-2008
https://lists.apache.org/thread.html/84e99dedad2ecb4676de93c3ab73a8a10882951ab6984f514707f3d9%40%3Cusers.tapestry.apache.org%3E
https://lists.apache.org/thread.html/bac8d6f9e1b4059b319d9cba6f33219a99b81623476ec896138f851c%40%3Cusers.tapestry.apache.org%3E
https://lists.apache.org/thread.html/r7d9c54beb1dc97dcccc58d9b5d31f0f7166f9a25ad1beba5f8091e0c%40%3Ccommits.tapestry.apache.org%3E
https://lists.apache.org/thread.html/r87523dd07886223aa086edc25fe9b8ddb9c1090f7db25b068dc30843%40%3Ccommits.tapestry.apache.org%3E
https://tapestry.apache.org/release-notes-536.html Vendor Advisory
cvelogic Threat Intelligence