CVE-2007-3715
Sun Java System Application Server and Web Server 7.0 through 9.0 before 20070710 do not properly process XSLT stylesheets in XSLT transforms in XML signatures, which allows context-dependent attackers to execute an arbitrary Java method via a crafted…
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (2.28%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
Sun Java System Application Server and Web Server 7.0 through 9.0 before 20070710 do not properly process XSLT stylesheets in XSLT transforms in XML signatures, which allows context-dependent attackers to execute an arbitrary Java method via a crafted stylesheet, a related issue to CVE-2007-3716.
- CVSS 2.0
- 9.3 HIGHAV:N/AC:M/Au:N/C:C/I:C/A:C
- EPSS
- 2.28% probability · 82th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-20
- Affected
- sun/java system application server · sun/java system web server
- Source
- cve@mitre.org
References
- http://osvdb.org/37248
- http://secunia.com/advisories/26023Vendor Advisory
- http://sunsolve.sun.com/search/document.do?assetkey=1-26-102992-1Patch, Vendor Advisory
- http://sunsolve.sun.com/search/document.do?assetkey=1-66-200054-1Vendor Advisory
- http://www.isecpartners.com/advisories/2007-04-dsig.txt
- http://www.isecpartners.com/files/XMLDSIG_Command_Injection.pdf
- http://www.securityfocus.com/archive/1/473552/100/0/threaded
- http://www.securityfocus.com/archive/1/473553/100/0/threaded
- http://www.securityfocus.com/bid/24850Patch
- http://www.vupen.com/english/advisories/2007/2493Vendor Advisory
- http://www.vupen.com/english/advisories/2007/2785Vendor Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/35335
- http://osvdb.org/37248
- http://secunia.com/advisories/26023Vendor Advisory
- http://sunsolve.sun.com/search/document.do?assetkey=1-26-102992-1Patch, Vendor Advisory
- http://sunsolve.sun.com/search/document.do?assetkey=1-66-200054-1Vendor Advisory
- http://www.isecpartners.com/advisories/2007-04-dsig.txt
- http://www.isecpartners.com/files/XMLDSIG_Command_Injection.pdf
- http://www.securityfocus.com/archive/1/473552/100/0/threaded
- http://www.securityfocus.com/archive/1/473553/100/0/threaded
- http://www.securityfocus.com/bid/24850Patch
- http://www.vupen.com/english/advisories/2007/2493Vendor Advisory
- http://www.vupen.com/english/advisories/2007/2785Vendor Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/35335
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.