Required CVE Record Information
Description
Sun Java System Portal Server 7.0 does not properly process XSLT stylesheets in XSLT transforms in XML signatures, which allows context-dependent attackers to execute an arbitrary Java method via a crafted stylesheet, a related issue to CVE-2007-3715.
References 7 Total
- securityfocus.com: 20070712 Whitepaper: Command Injection in XML Digital Signatures and Encryption mailing-list
- http://www.isecpartners.com/files/XMLDSIG_Command_Injection.pdf
- secunia.com: 26327 third-party-advisory
- exchange.xforce.ibmcloud.com: sun-jsps-xslt-code-execution(35811) vdb-entry
- securitytracker.com: 1018513 vdb-entry
- http://www.isecpartners.com/advisories/2007-04-dsig.txt
- sunsolve.sun.com: 103015 vendor-advisory
Updated:
This container includes required additional information provided by the CVE Program for this vulnerability.
References 7 Total
- securityfocus.com: 20070712 Whitepaper: Command Injection in XML Digital Signatures and Encryption mailing-listx_transferred
- http://www.isecpartners.com/files/XMLDSIG_Command_Injection.pdf x_transferred
- secunia.com: 26327 third-party-advisoryx_transferred
- exchange.xforce.ibmcloud.com: sun-jsps-xslt-code-execution(35811) vdb-entryx_transferred
- securitytracker.com: 1018513 vdb-entryx_transferred
- http://www.isecpartners.com/advisories/2007-04-dsig.txt x_transferred
- sunsolve.sun.com: 103015 vendor-advisoryx_transferred