Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-hqwp-wj7r-gf8j

Опубликовано: 01 мая 2022
Источник: github
Github: Не прошло ревью

Описание

Sun Java System Access Manager 6.3 through 7.1 and Sun Java System Identity Server 6.1 and 6.2 do not properly process XSLT stylesheets in XSLT transforms in XML signatures, which allows context-dependent attackers to execute arbitrary code via a crafted stylesheet, a related issue to CVE-2007-3715, CVE-2007-3716, and CVE-2007-4289.

Sun Java System Access Manager 6.3 through 7.1 and Sun Java System Identity Server 6.1 and 6.2 do not properly process XSLT stylesheets in XSLT transforms in XML signatures, which allows context-dependent attackers to execute arbitrary code via a crafted stylesheet, a related issue to CVE-2007-3715, CVE-2007-3716, and CVE-2007-4289.

EPSS

Процентиль: 75%
0.00895
Низкий

Дефекты

CWE-20

Связанные уязвимости

nvd
больше 17 лет назад

Sun Java System Access Manager 6.3 through 7.1 and Sun Java System Identity Server 6.1 and 6.2 do not properly process XSLT stylesheets in XSLT transforms in XML signatures, which allows context-dependent attackers to execute arbitrary code via a crafted stylesheet, a related issue to CVE-2007-3715, CVE-2007-3716, and CVE-2007-4289.

EPSS

Процентиль: 75%
0.00895
Низкий

Дефекты

CWE-20