CVE-2007-3503
published 2007-06-30CVE-2007-3503: The Javadoc tool in Sun JDK 6 and JDK 5.0 Update 11 can generate HTML documentation pages that contain cross-site scripting (XSS) vulnerabilities, which allows…
PriorityP417medium4.3CVSS 2.0
AVNACMAuNCNIPAN
EPSS
3.05%
86.2th percentile
The Javadoc tool in Sun JDK 6 and JDK 5.0 Update 11 can generate HTML documentation pages that contain cross-site scripting (XSS) vulnerabilities, which allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
Affected
35 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| hitachi | ucosminexus_application_server_enterprise | — | — |
| hitachi | ucosminexus_application_server_enterprise | — | — |
| hitachi | ucosminexus_application_server_enterprise | — | — |
| hitachi | ucosminexus_application_server_enterprise | — | — |
| hitachi | ucosminexus_application_server_enterprise | — | — |
| hitachi | ucosminexus_application_server_enterprise | — | — |
| hitachi | ucosminexus_application_server_enterprise | — | — |
| hitachi | ucosminexus_application_server_enterprise | — | — |
| hitachi | ucosminexus_application_server_standard | — | — |
| hitachi | ucosminexus_application_server_standard | — | — |
| hitachi | ucosminexus_application_server_standard | — | — |
| hitachi | ucosminexus_application_server_standard | — | — |
| hitachi | ucosminexus_application_server_standard | — | — |
| hitachi | ucosminexus_application_server_standard | — | — |
| hitachi | ucosminexus_application_server_standard | — | — |
| hitachi | ucosminexus_application_server_standard | — | — |
| hitachi | ucosminexus_developer_standard | — | — |
| hitachi | ucosminexus_developer_standard | — | — |
| hitachi | ucosminexus_developer_standard | — | — |
| hitachi | ucosminexus_developer_standard | — | — |
| hitachi | ucosminexus_developer_standard | — | — |
| hitachi | ucosminexus_developer_standard | — | — |
| hitachi | ucosminexus_developer_standard | — | — |
| hitachi | ucosminexus_developer_standard | — | — |
| hitachi | ucosminexus_developer_standard | — | — |
CVSS provenance
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:N/I:P/A:N
vendor_redhat4.3MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-7m4h-vmxp-2j43: The Javadoc tool in Sun JDK 6 and JDK 5
ghsa_unreviewed·2022-05-01
CVE-2007-3503 [MEDIUM] CWE-79 GHSA-7m4h-vmxp-2j43: The Javadoc tool in Sun JDK 6 and JDK 5
The Javadoc tool in Sun JDK 6 and JDK 5.0 Update 11 can generate HTML documentation pages that contain cross-site scripting (XSS) vulnerabilities, which allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
GHSA
GHSA-wv5h-grg4-29jw: The javadoc tool in Cosminexus Developer's Kit for Java in Cosminexus 7 and 7
ghsa_unreviewed·2022-05-01·CVSS 4.3
CVE-2007-4760 [MEDIUM] CWE-79 GHSA-wv5h-grg4-29jw: The javadoc tool in Cosminexus Developer's Kit for Java in Cosminexus 7 and 7
The javadoc tool in Cosminexus Developer's Kit for Java in Cosminexus 7 and 7.5 can generate HTML documents that contain cross-site scripting (XSS) vulnerabilities, which allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. NOTE: this is probably the same issue as CVE-2007-3503.
Red Hat
HTML files generated with Javadoc are vulnerable to a XSS
vendor_redhat·2007-06-28·CVSS 4.3
CVE-2007-3503 [MEDIUM] CWE-79 HTML files generated with Javadoc are vulnerable to a XSS
HTML files generated with Javadoc are vulnerable to a XSS
The Javadoc tool in Sun JDK 6 and JDK 5.0 Update 11 can generate HTML documentation pages that contain cross-site scripting (XSS) vulnerabilities, which allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
No detection rules found.
No public exploits indexed.
http://dev2dev.bea.com/pub/advisory/248http://docs.info.apple.com/article.html?artnum=307177http://lists.apple.com/archives/Security-announce/2007/Dec/msg00001.htmlhttp://osvdb.org/36488http://secunia.com/advisories/25769http://secunia.com/advisories/26314http://secunia.com/advisories/26369http://secunia.com/advisories/26631http://secunia.com/advisories/26645http://secunia.com/advisories/26933http://secunia.com/advisories/27203http://secunia.com/advisories/28115http://sunsolve.sun.com/search/document.do?assetkey=1-26-102958-1http://www.gentoo.org/security/en/glsa/glsa-200709-15.xmlhttp://www.redhat.com/support/errata/RHSA-2007-0818.htmlhttp://www.redhat.com/support/errata/RHSA-2007-0829.htmlhttp://www.redhat.com/support/errata/RHSA-2007-0956.htmlhttp://www.securityfocus.com/bid/24690http://www.securitytracker.com/id?1018327http://www.vupen.com/english/advisories/2007/2383http://www.vupen.com/english/advisories/2007/3009http://www.vupen.com/english/advisories/2007/4224https://exchange.xforce.ibmcloud.com/vulnerabilities/35168https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10704http://dev2dev.bea.com/pub/advisory/248http://docs.info.apple.com/article.html?artnum=307177http://lists.apple.com/archives/Security-announce/2007/Dec/msg00001.htmlhttp://osvdb.org/36488http://secunia.com/advisories/25769http://secunia.com/advisories/26314http://secunia.com/advisories/26369http://secunia.com/advisories/26631http://secunia.com/advisories/26645http://secunia.com/advisories/26933http://secunia.com/advisories/27203http://secunia.com/advisories/28115http://sunsolve.sun.com/search/document.do?assetkey=1-26-102958-1http://www.gentoo.org/security/en/glsa/glsa-200709-15.xmlhttp://www.redhat.com/support/errata/RHSA-2007-0818.htmlhttp://www.redhat.com/support/errata/RHSA-2007-0829.htmlhttp://www.redhat.com/support/errata/RHSA-2007-0956.htmlhttp://www.securityfocus.com/bid/24690http://www.securitytracker.com/id?1018327http://www.vupen.com/english/advisories/2007/2383http://www.vupen.com/english/advisories/2007/3009http://www.vupen.com/english/advisories/2007/4224https://exchange.xforce.ibmcloud.com/vulnerabilities/35168https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10704
2007-06-30
Published