Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2007-3715

Опубликовано: 11 июл. 2007
Источник: nvd
CVSS2: 9.3
EPSS Низкий

Описание

Sun Java System Application Server and Web Server 7.0 through 9.0 before 20070710 do not properly process XSLT stylesheets in XSLT transforms in XML signatures, which allows context-dependent attackers to execute an arbitrary Java method via a crafted stylesheet, a related issue to CVE-2007-3716.

Уязвимые конфигурации

Конфигурация 1

Одно из

cpe:2.3:a:sun:java_system_application_server:8.2:*:enterprise:*:*:*:*:*
cpe:2.3:a:sun:java_system_application_server:8.2:*:enterprise_linux:*:*:*:*:*
cpe:2.3:a:sun:java_system_application_server:8.2:*:enterprise_sparc:*:*:*:*:*
cpe:2.3:a:sun:java_system_application_server:8.2:*:enterprise_windows:*:*:*:*:*
cpe:2.3:a:sun:java_system_application_server:8.2:*:enterprise_x86:*:*:*:*:*
cpe:2.3:a:sun:java_system_application_server:8.2:*:platform:*:*:*:*:*
cpe:2.3:a:sun:java_system_application_server:8.2:*:platform_linux:*:*:*:*:*
cpe:2.3:a:sun:java_system_application_server:8.2:*:platform_sparc:*:*:*:*:*
cpe:2.3:a:sun:java_system_application_server:8.2:*:platform_windows:*:*:*:*:*
cpe:2.3:a:sun:java_system_application_server:8.2:*:platform_x86:*:*:*:*:*
cpe:2.3:a:sun:java_system_application_server:9.0:*:platform:*:*:*:*:*
cpe:2.3:a:sun:java_system_application_server:9.0:*:platform_linux:*:*:*:*:*
cpe:2.3:a:sun:java_system_application_server:9.0:*:platform_sparc:*:*:*:*:*
cpe:2.3:a:sun:java_system_application_server:9.0:*:platform_windows:*:*:*:*:*
cpe:2.3:a:sun:java_system_application_server:9.0:*:platform_x86:*:*:*:*:*
cpe:2.3:a:sun:java_system_web_server:7.0:*:*:*:*:*:*:*
cpe:2.3:a:sun:java_system_web_server:7.0:*:hp_ux:*:*:*:*:*
cpe:2.3:a:sun:java_system_web_server:7.0:*:linux:*:*:*:*:*
cpe:2.3:a:sun:java_system_web_server:7.0:*:sparc:*:*:*:*:*
cpe:2.3:a:sun:java_system_web_server:7.0:*:windows:*:*:*:*:*
cpe:2.3:a:sun:java_system_web_server:7.0:*:x86:*:*:*:*:*

EPSS

Процентиль: 79%
0.0121
Низкий

9.3 Critical

CVSS2

Дефекты

CWE-20

Связанные уязвимости

github
почти 4 года назад

Sun Java System Application Server and Web Server 7.0 through 9.0 before 20070710 do not properly process XSLT stylesheets in XSLT transforms in XML signatures, which allows context-dependent attackers to execute an arbitrary Java method via a crafted stylesheet, a related issue to CVE-2007-3716.

EPSS

Процентиль: 79%
0.0121
Низкий

9.3 Critical

CVSS2

Дефекты

CWE-20