XSLT Transform Vulnerability in Sun Java System Application Server and Web Server
CVE-2007-3715

Currently unrated

What is CVE-2007-3715?

Certain versions of Sun Java System Application Server and Web Server prior to July 10, 2007, exhibit a flaw in how they handle XSLT stylesheets during XML signature transformations. This vulnerability permits context-dependent attackers to leverage crafted stylesheets to execute arbitrary Java methods, posing significant risks to affected installations. Attackers may exploit this flaw to gain unauthorized access or execute malicious code within the application environment, thus emphasizing the need for timely security updates and proper mitigation strategies.

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.