Executive Summary

Summary
Title Sun Alert 102992 Security Vulnerability in Processing XSLT Stylesheets Affects Sun Java System Application Server and Web Server
Informations
Name SUN-102992 First vendor Publication 2007-07-10
Vendor Sun Last vendor Modification 2007-10-26
Severity (Vendor) N/A Revision N/A

Security-Database Scoring CVSS v3

Cvss vector : N/A
Overall CVSS Score NA
Base Score NA Environmental Score NA
impact SubScore NA Temporal Score NA
Exploitabality Sub Score NA
 
Calculate full CVSS 3.0 Vectors scores

Security-Database Scoring CVSS v2

Cvss vector : (AV:N/AC:M/Au:N/C:C/I:C/A:C)
Cvss Base Score 9.3 Attack Range Network
Cvss Impact Score 10 Attack Complexity Medium
Cvss Expoit Score 8.6 Authentication None Required
Calculate full CVSS 2.0 Vectors scores

Detail

Product: Sun Java System Application Server Standard Edition 8.2, Sun Java System Application Server Enterprise Edition 8.2, Sun Java System Application Server Platform Edition 9.0 Update 1, Sun Java System Application Server PE 9 , Sun Java System Web Server 7.0

Certain releases of Sun Java System Application Server and Sun Java System Web Server (listed in "Contributing Factors") do not securely process XSLT stylesheets contained in XSLT Transforms in XML Signatures. This could allow malicious XLST stylesheets to be executed which may, for example, allow execution of an arbitrary Java method.

Sun acknowledges, with thanks, Brad Hill of iSEC Partners, for bringing this issue to our attention.

Avoidance: Patch
State: Resolved
First released: 10-Jul-2007

Original Source

Url : http://blogs.sun.com/security/entry/sun_alert_102992_security_vulnerability

CWE : Common Weakness Enumeration

% Id Name
100 % CWE-20 Improper Input Validation

CPE : Common Platform Enumeration

TypeDescriptionCount
Application 15
Application 6

Open Source Vulnerability Database (OSVDB)

Id Description
37248 Sun Java System Web / Application Server Crafted XSLT Stylesheet Arbitrary Ja...

Nessus® Vulnerability Scanner

Date Description
2007-10-12 Name : The remote host is missing Sun Security Patch number 125437-22
File : solaris10_125437.nasl - Type : ACT_GATHER_INFO
2007-10-12 Name : The remote host is missing Sun Security Patch number 125438-22
File : solaris10_x86_125438.nasl - Type : ACT_GATHER_INFO
2007-10-12 Name : The remote host is missing Sun Security Patch number 125437-22
File : solaris8_125437.nasl - Type : ACT_GATHER_INFO
2007-10-12 Name : The remote host is missing Sun Security Patch number 125437-22
File : solaris9_125437.nasl - Type : ACT_GATHER_INFO
2007-10-12 Name : The remote host is missing Sun Security Patch number 125438-22
File : solaris9_x86_125438.nasl - Type : ACT_GATHER_INFO