CVE-2007-3715
Last modified
CVE-2007-3715 is a vulnerability of currently unknown severity. Sun Java System Application Server and Web Server 7.0 through 9.0 before 20070710 do not properly process XSLT stylesheets in XSLT transforms in XML signatures, which allows context-dependent attackers to execute an arbitrary Java method via a crafted stylesheet, a related issue to CVE-2007-3716.. EPSS estimates a 2.29% chance of exploitation in the next 30 days.
Description
Sun Java System Application Server and Web Server 7.0 through 9.0 before 20070710 do not properly process XSLT stylesheets in XSLT transforms in XML signatures, which allows context-dependent attackers to execute an arbitrary Java method via a crafted stylesheet, a related issue to CVE-2007-3716.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Sun | Java System Application Server | 8.2 |
| Sun | Java System Application Server | 9.0 |
| Sun | Java System Web Server | 7.0 |
References
- http://secunia.com/advisories/26023Vendor Advisory
- http://sunsolve.sun.com/search/document.do?assetkey=1-26-102992-1Patch, Vendor Advisory
- http://www.vupen.com/english/advisories/2007/2493Vendor Advisory
- http://www.vupen.com/english/advisories/2007/2785Vendor Advisory
- http://secunia.com/advisories/26023Vendor Advisory
- http://sunsolve.sun.com/search/document.do?assetkey=1-26-102992-1Patch, Vendor Advisory
- http://www.vupen.com/english/advisories/2007/2493Vendor Advisory
- http://www.vupen.com/english/advisories/2007/2785Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2007-3715?
How severe is CVE-2007-3715?
How do I fix CVE-2007-3715?
Are you affected by CVE-2007-3715?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
