SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2007-3715

Sun Java System Application Server and Web Server 7.0 through 9.0 before 20070710 do not properly process XSLT stylesheets in XSLT transforms in XML signatures, which allows context-dependent attackers to execute an arbitrary Java method via a crafted…

HIGH 9.3EPSS 2.28%

Does this matter?

High impact if exploited, but EPSS currently rates exploitation as unlikely (2.28%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.

Description

Sun Java System Application Server and Web Server 7.0 through 9.0 before 20070710 do not properly process XSLT stylesheets in XSLT transforms in XML signatures, which allows context-dependent attackers to execute an arbitrary Java method via a crafted stylesheet, a related issue to CVE-2007-3716.

CVSS 2.0
9.3 HIGHAV:N/AC:M/Au:N/C:C/I:C/A:C
EPSS
2.28% probability · 82th percentile
CISA KEV
Not listed
Weakness
CWE-20
Affected
sun/java system application server · sun/java system web server
Source
cve@mitre.org

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.