cbcvebase.
CVE-2007-3716
published 2007-07-11

CVE-2007-3716: The Java XML Digital Signature implementation in Sun JDK and JRE 6 before Update 2 does not properly process XSLT stylesheets in XSLT transforms in XML…

PriorityP340critical9.3CVSS 2.0
AVNACMAuNCCICAC
EPSS
3.55%
88.0th percentile
The Java XML Digital Signature implementation in Sun JDK and JRE 6 before Update 2 does not properly process XSLT stylesheets in XSLT transforms in XML signatures, which allows context-dependent attackers to execute arbitrary code via a crafted stylesheet, a related issue to CVE-2007-3715.

Affected

10 ranges
VendorProductVersion rangeFixed in
sunjava_system_access_manager
sunjava_system_access_manager
sunjava_system_access_manager
sunjava_system_application_server
sunjava_system_application_server
sunjava_system_identity_server
sunjava_system_identity_server
sunjava_system_web_server
sunjdk<= 6
sunjre<= 6
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.