Sun Java System Application Server and Web Server 7.0 through 9.0 before 20070710 do not properly process XSLT stylesheets in XSLT transforms in XML signatures, which allows context-dependent attackers to execute an arbitrary Java method via a crafted stylesheet, a related issue to CVE-2007-3716.
The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.
Link | Tags |
---|---|
http://www.securityfocus.com/archive/1/473552/100/0/threaded | mailing list |
http://secunia.com/advisories/26023 | third party advisory vendor advisory |
http://www.securityfocus.com/archive/1/473553/100/0/threaded | mailing list |
http://www.isecpartners.com/files/XMLDSIG_Command_Injection.pdf | |
https://exchange.xforce.ibmcloud.com/vulnerabilities/35335 | vdb entry |
http://www.isecpartners.com/advisories/2007-04-dsig.txt | |
http://osvdb.org/37248 | vdb entry |
http://www.securityfocus.com/bid/24850 | vdb entry patch |
http://www.vupen.com/english/advisories/2007/2493 | vdb entry vendor advisory |
http://sunsolve.sun.com/search/document.do?assetkey=1-26-102992-1 | patch vendor advisory |
http://www.vupen.com/english/advisories/2007/2785 | vdb entry vendor advisory |
http://sunsolve.sun.com/search/document.do?assetkey=1-66-200054-1 | vendor advisory |