CVE-2007-3716Improper Input Validation in Java System Access Manager

Severity
9.3CRITICALNVD
NVD7.5
EPSS
4.8%
top 10.48%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJul 11
Latest updateMay 1

Description

The Java XML Digital Signature implementation in Sun JDK and JRE 6 before Update 2 does not properly process XSLT stylesheets in XSLT transforms in XML signatures, which allows context-dependent attackers to execute arbitrary code via a crafted stylesheet, a related issue to CVE-2007-3715.

CVSS vector

AV:N/AC:M/C:C/I:C/A:CExploitability: 8.6 | Impact: 10.0

Affected Packages6 packages

Patches

🔴Vulnerability Details

6
GHSA
GHSA-hqwp-wj7r-gf8j: Sun Java System Access Manager 62022-05-01
GHSA
GHSA-m7vm-xh92-2mwf: Sun Java System Application Server and Web Server 72022-05-01
GHSA
GHSA-5fxq-f64v-57fq: The Java XML Digital Signature implementation in Sun JDK and JRE 6 before Update 2 does not properly process XSLT stylesheets in XSLT transforms in XM2022-05-01
CVEList
CVE-2008-2945: Sun Java System Access Manager 62008-06-30
CVEList
CVE-2007-3715: Sun Java System Application Server and Web Server 72007-07-11
CVE-2007-3716 — Improper Input Validation | cvebase