CVE-2008-2945
Published Jun 30, 2008
Last updated 7 years ago
Overview
- Description
- Sun Java System Access Manager 6.3 through 7.1 and Sun Java System Identity Server 6.1 and 6.2 do not properly process XSLT stylesheets in XSLT transforms in XML signatures, which allows context-dependent attackers to execute arbitrary code via a crafted stylesheet, a related issue to CVE-2007-3715, CVE-2007-3716, and CVE-2007-4289.
- Source
- cve@mitre.org
- NVD status
- Modified
Social media
- Hype score
- Not currently trending
Risk scores
CVSS 2.0
- Type
- Primary
- Base score
- 7.5
- Impact score
- 6.4
- Exploitability score
- 10
- Vector string
- AV:N/AC:L/Au:N/C:P/I:P/A:P
Weaknesses
- nvd@nist.gov
- CWE-20
Configurations
[ { "nodes": [ { "negate": false, "cpeMatch": [ { "criteria": "cpe:2.3:a:sun:java_system_access_manager:6.3:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "31DEED4B-0AFF-49A2-9DDA-B4D74E3B29A0" }, { "criteria": "cpe:2.3:a:sun:java_system_access_manager:7.0:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "D88350FE-285D-4144-B7DC-5E1F8579CC56" }, { "criteria": "cpe:2.3:a:sun:java_system_access_manager:7.1:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "0B5B089E-62AC-44E5-9462-DC439C7AA8A5" }, { "criteria": "cpe:2.3:a:sun:java_system_identity_server:6.1:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "DB8DC1D1-AF26-48BC-A773-5D7CAC70C7D9" }, { "criteria": "cpe:2.3:a:sun:java_system_identity_server:6.2:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "9770CADB-E22A-425C-A35B-AFC52CE53C88" } ], "operator": "OR" } ] } ]