Executive Summary
Summary | |
---|---|
Title | Sun Alert 103015 A Security Vulnerability in Processing XSLT Style Sheets Affects Sun Java System Portal Server Software 7.0 |
Informations | |||
---|---|---|---|
Name | SUN-103015 | First vendor Publication | 2007-08-03 |
Vendor | Sun | Last vendor Modification | 2007-08-04 |
Severity (Vendor) | N/A | Revision | N/A |
Security-Database Scoring CVSS v3
Cvss vector : N/A | |||
---|---|---|---|
Overall CVSS Score | NA | ||
Base Score | NA | Environmental Score | NA |
impact SubScore | NA | Temporal Score | NA |
Exploitabality Sub Score | NA | ||
Calculate full CVSS 3.0 Vectors scores |
Security-Database Scoring CVSS v2
Cvss vector : (AV:N/AC:M/Au:N/C:P/I:P/A:P) | |||
---|---|---|---|
Cvss Base Score | 6.8 | Attack Range | Network |
Cvss Impact Score | 6.4 | Attack Complexity | Medium |
Cvss Expoit Score | 8.6 | Authentication | None Required |
Calculate full CVSS 2.0 Vectors scores |
Detail
Product: Sun Java System Portal Server 7 Sun Java System Portal Server Software 7.0 may not securely process XSLT style sheets contained in XSLT Transforms in XML Signatures. This may allow malicious XLST style sheets to be executed. For example, an arbitrary Java method could be executed due to this vulnerability. Sun acknowledges, with thanks, Brad Hill of iSEC Partners, for bringing this issue to our attention. Avoidance: Patch State: Resolved First released: 03-Aug-2007 |
Original Source
Url : http://blogs.sun.com/security/entry/sun_alert_103015_a_security |
CPE : Common Platform Enumeration
Type | Description | Count |
---|---|---|
Application | 1 |
Open Source Vulnerability Database (OSVDB)
Id | Description |
---|---|
37251 | Sun Java System Portal Server Crafted XSLT Stylesheet Arbitrary Java Method E... |
Nessus® Vulnerability Scanner
Date | Description |
---|---|
2007-10-15 | Name : The remote host is missing Sun Security Patch number 121913-20 File : solaris8_121913.nasl - Type : ACT_GATHER_INFO |
2007-10-12 | Name : The remote host is missing Sun Security Patch number 121913-20 File : solaris10_121913.nasl - Type : ACT_GATHER_INFO |
2007-10-12 | Name : The remote host is missing Sun Security Patch number 121914-20 File : solaris10_x86_121914.nasl - Type : ACT_GATHER_INFO |
2007-10-12 | Name : The remote host is missing Sun Security Patch number 121914-20 File : solaris8_x86_121914.nasl - Type : ACT_GATHER_INFO |
2007-10-12 | Name : The remote host is missing Sun Security Patch number 121913-20 File : solaris9_121913.nasl - Type : ACT_GATHER_INFO |
2007-10-12 | Name : The remote host is missing Sun Security Patch number 121914-20 File : solaris9_x86_121914.nasl - Type : ACT_GATHER_INFO |
Alert History
Date | Informations |
---|---|
2016-04-26 13:53:28 |
|