cbcvebase.
CVE-2007-4289
published 2007-08-09

CVE-2007-4289: Sun Java System Portal Server 7.0 does not properly process XSLT stylesheets in XSLT transforms in XML signatures, which allows context-dependent attackers to…

PriorityP430medium6.8CVSS 2.0
AVNACMAuNCPIPAP
EPSS
1.67%
74.0th percentile
Sun Java System Portal Server 7.0 does not properly process XSLT stylesheets in XSLT transforms in XML signatures, which allows context-dependent attackers to execute an arbitrary Java method via a crafted stylesheet, a related issue to CVE-2007-3715.

Affected

6 ranges
VendorProductVersion rangeFixed in
sunjava_system_access_manager
sunjava_system_access_manager
sunjava_system_access_manager
sunjava_system_identity_server
sunjava_system_identity_server
sunjava_system_portal_server
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.