cbcvebase.
CVE-2007-3715
published 2007-07-11

CVE-2007-3715: Sun Java System Application Server and Web Server 7.0 through 9.0 before 20070710 do not properly process XSLT stylesheets in XSLT transforms in XML…

PriorityP338critical9.3CVSS 2.0
AVNACMAuNCCICAC
EPSS
2.29%
81.2th percentile
Sun Java System Application Server and Web Server 7.0 through 9.0 before 20070710 do not properly process XSLT stylesheets in XSLT transforms in XML signatures, which allows context-dependent attackers to execute an arbitrary Java method via a crafted stylesheet, a related issue to CVE-2007-3716.

Affected

11 ranges
VendorProductVersion rangeFixed in
sunjava_system_access_manager
sunjava_system_access_manager
sunjava_system_access_manager
sunjava_system_application_server
sunjava_system_application_server
sunjava_system_identity_server
sunjava_system_identity_server
sunjava_system_portal_server
sunjava_system_web_server
sunjdk<= 6
sunjre<= 6
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.