CVE-2008-2945

high
New! CVE Severity Now Using CVSS v3

The calculated severity for CVEs has been updated to use CVSS v3 by default. CVEs that do not have a CVSS v3 score will fall back CVSS v2 for calculating severity. Severity display preferences can be toggled in the settings dropdown.

Description

Sun Java System Access Manager 6.3 through 7.1 and Sun Java System Identity Server 6.1 and 6.2 do not properly process XSLT stylesheets in XSLT transforms in XML signatures, which allows context-dependent attackers to execute arbitrary code via a crafted stylesheet, a related issue to CVE-2007-3715, CVE-2007-3716, and CVE-2007-4289.

References

http://secunia.com/advisories/30893

http://sunsolve.sun.com/search/document.do?assetkey=1-26-201538-1

http://support.avaya.com/elmodocs2/security/ASA-2008-294.htm

http://www.securityfocus.com/bid/29988

http://www.securitytracker.com/id?1020380

http://www.vupen.com/english/advisories/2008/1967/references

https://exchange.xforce.ibmcloud.com/vulnerabilities/43429

Details

Source: MITRE

Published: 2008-06-30

Updated: 2017-08-08

Type: CWE-20

Risk Information

CVSS v2

Base Score: 7.5

Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Impact Score: 6.4

Exploitability Score: 10

Severity: HIGH

Tenable Plugins

View all (14 total)

IDNameProductFamilySeverity
107950Solaris 10 (x86) : 126357-06NessusSolaris Local Security Checks
critical
107871Solaris 10 (x86) : 120955-12NessusSolaris Local Security Checks
critical
107450Solaris 10 (sparc) : 126356-06NessusSolaris Local Security Checks
critical
107369Solaris 10 (sparc) : 120954-12NessusSolaris Local Security Checks
critical
38126Solaris 10 (x86) : 120955-12 (deprecated)NessusSolaris Local Security Checks
critical
38005Solaris 9 (x86) : 120955-12NessusSolaris Local Security Checks
critical
37533Solaris 9 (sparc) : 120954-12NessusSolaris Local Security Checks
critical
37271Solaris 8 (sparc) : 120954-12NessusSolaris Local Security Checks
critical
36756Solaris 10 (sparc) : 120954-12 (deprecated)NessusSolaris Local Security Checks
critical
30177Solaris 9 (sparc) : 117586-22NessusSolaris Local Security Checks
high
30176Solaris 8 (sparc) : 117586-22NessusSolaris Local Security Checks
high
23615Solaris 5.9 (x86) : 120091-15NessusSolaris Local Security Checks
high
23511Solaris 9 (sparc) : 115766-15NessusSolaris Local Security Checks
high
23374Solaris 8 (sparc) : 115766-15NessusSolaris Local Security Checks
high