CVE-2008-2945
Last modified
CVE-2008-2945 is a vulnerability of currently unknown severity. Sun Java System Access Manager 6.3 through 7.1 and Sun Java System Identity Server 6.1 and 6.2 do not properly process XSLT stylesheets in XSLT transforms in XML signatures, which allows context-dependent attackers to execute arbitrary code via a crafted stylesheet, a related issue to CVE-2007-3715, CVE-2007-3716, and CVE-2007-4289.. EPSS estimates a 2.80% chance of exploitation in the next 30 days.
Description
Sun Java System Access Manager 6.3 through 7.1 and Sun Java System Identity Server 6.1 and 6.2 do not properly process XSLT stylesheets in XSLT transforms in XML signatures, which allows context-dependent attackers to execute arbitrary code via a crafted stylesheet, a related issue to CVE-2007-3715, CVE-2007-3716, and CVE-2007-4289.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Sun | Java System Access Manager | 6.3 |
| Sun | Java System Access Manager | 7.0 |
| Sun | Java System Access Manager | 7.1 |
| Sun | Java System Identity Server | 6.1 |
| Sun | Java System Identity Server | 6.2 |
References
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2008-2945?
How severe is CVE-2008-2945?
How do I fix CVE-2008-2945?
Are you affected by CVE-2008-2945?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
