CVE-2007-3715
Last modified
CVE-2007-3715 is a vulnerability of currently unknown severity. Sun Java System Application Server and Web Server 7.0 through 9.0 before 20070710 do not properly process XSLT stylesheets in XSLT transforms in XML signatures, which allows context-dependent attackers to execute an arbitrary Java method via a crafted stylesheet, a related issue to CVE-2007-3716.. EPSS estimates a 2.29% chance of exploitation in the next 30 days.
Description
Sun Java System Application Server and Web Server 7.0 through 9.0 before 20070710 do not properly process XSLT stylesheets in XSLT transforms in XML signatures, which allows context-dependent attackers to execute an arbitrary Java method via a crafted stylesheet, a related issue to CVE-2007-3716.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Sun | Java System Application Server | 8.2 |
| Sun | Java System Application Server | 9.0 |
| Sun | Java System Web Server | 7.0 |
References
- http://secunia.com/advisories/26023Vendor Advisory
- http://sunsolve.sun.com/search/document.do?assetkey=1-26-102992-1Patch, Vendor Advisory
- http://www.vupen.com/english/advisories/2007/2493Vendor Advisory
- http://www.vupen.com/english/advisories/2007/2785Vendor Advisory
- http://secunia.com/advisories/26023Vendor Advisory
- http://sunsolve.sun.com/search/document.do?assetkey=1-26-102992-1Patch, Vendor Advisory
- http://www.vupen.com/english/advisories/2007/2493Vendor Advisory
- http://www.vupen.com/english/advisories/2007/2785Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2007-3715?
How severe is CVE-2007-3715?
How do I fix CVE-2007-3715?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2007
- CVE-2007-3709CRLF injection vulnerability in the redirect function in url…
- CVE-2007-3710PHP remote file inclusion vulnerability in example/gamedemo/…
- CVE-2007-3711Unspecified vulnerability in TOS 2.1.x, 2.2.x before 2.2.5, …
- CVE-2007-3712Multiple cross-site scripting (XSS) vulnerabilities in Hidde…
- CVE-2007-3713Multiple buffer overflows in Konst CenterICQ 4.9.11 through …
- CVE-2007-3714Directory traversal vulnerability in Ada Image Server (ImgSv…
- CVE-2007-3716The Java XML Digital Signature implementation in Sun JDK and…
- CVE-2007-3717rcp on Sun Solaris 8, 9, and 10 before 20070710 does not pro…
- CVE-2007-3718Multiple unspecified vulnerabilities in the SVG parsing engi…
- CVE-2007-3719The process scheduler in the Linux kernel 2.6.16 gives prefe…
- CVE-2007-3720The process scheduler in the Linux kernel 2.4 performs sched…
- CVE-2007-3721The ULE process scheduler in the FreeBSD kernel gives prefer…
Are you affected by CVE-2007-3715?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
