CVE-2007-3715

Sun Java System Application Server and Web Server 7.0-9.0 - Arbitrary Java Method Execution via XSLT Stylesheet

Title source: llm
STIX 2.1

Description

Sun Java System Application Server and Web Server 7.0 through 9.0 before 20070710 do not properly process XSLT stylesheets in XSLT transforms in XML signatures, which allows context-dependent attackers to execute an arbitrary Java method via a crafted stylesheet, a related issue to CVE-2007-3716.

References (12)

Core 12
Core References
Third Party Advisory, VDB Entry mailing-list x_refsource_bugtraq
http://www.securityfocus.com/archive/1/473552/100/0/threaded
Vendor Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/26023
Third Party Advisory, VDB Entry mailing-list x_refsource_bugtraq
http://www.securityfocus.com/archive/1/473553/100/0/threaded
Third Party Advisory, VDB Entry vdb-entry x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/35335
Third Party Advisory, VDB Entry vdb-entry x_refsource_osvdb
http://osvdb.org/37248
Patch vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/24850
Vendor Advisory vdb-entry x_refsource_vupen
http://www.vupen.com/english/advisories/2007/2493
Patch, Vendor Advisory vendor-advisory x_refsource_sunalert
http://sunsolve.sun.com/search/document.do?assetkey=1-26-102992-1
Vendor Advisory vdb-entry x_refsource_vupen
http://www.vupen.com/english/advisories/2007/2785
Vendor Advisory vendor-advisory x_refsource_sunalert
http://sunsolve.sun.com/search/document.do?assetkey=1-66-200054-1

Scores

EPSS 0.0126
EPSS Percentile 79.7%

Details

CWE
CWE-20
Status published
Products (3)
sun/java_system_application_server 8.2 (10 CPE variants)
sun/java_system_application_server 9.0 (5 CPE variants)
sun/java_system_web_server 7.0 (6 CPE variants)
Published Jul 11, 2007
Tracked Since Feb 18, 2026