Sun Java System Server XSLT Processing Remote Java Method Execution Vulnerability

BID:24850

Info

Sun Java System Server XSLT Processing Remote Java Method Execution Vulnerability

Bugtraq ID: 24850
Class: Design Error
CVE: CVE-2007-3715
Remote: Yes
Local: No
Published: Jul 10 2007 12:00AM
Updated: Oct 26 2007 10:26PM
Credit: Brad Hill of iSEC Partners reported this issue to the vendor.
Vulnerable: Sun SDK (Linux Production Release) 1.6 _1
Sun SDK (Linux Production Release) 1.5 _11
Sun SDK (Linux Production Release) 1.5 _06
Sun SDK (Linux Production Release) 1.5 _05
Sun SDK (Linux Production Release) 1.5 _04
Sun Java System Web Server 7.0
Sun Java System Portal Server 7
Sun Java System Application Server Standard Edition 8.2
Sun Java System Application Server Platform Edition 9.0 Update 1
Sun Java System Application Server Platform Edition 9.0
Sun Java System Application Server Platform Edition 8.2
Sun Java System Application Server Enterprise Edition 8.2
Sun Java 2 Standard Edition SDK 5.0 Update 9
Sun Java 2 Standard Edition SDK 5.0 Update 8
Sun Java 2 Standard Edition SDK 5.0 Update 7
Sun Java 2 Standard Edition SDK 5.0 Update 3
Sun Java 2 Standard Edition SDK 5.0 Update 2
Sun Java 2 Standard Edition SDK 5.0 Update 12
Sun Java 2 Standard Edition SDK 5.0 Update 10
Sun Java 2 Standard Edition SDK 5.0 Update 1
Sun Java 2 Standard Edition SDK 5.0
Sun Java 2 Runtime Environment 6.0 Update 1
Sun Java 2 Runtime Environment 5.0.Update 9
Sun Java 2 Runtime Environment 5.0.Update 12
Sun Java 2 Runtime Environment 5.0.Update 10
Sun Java 2 Runtime Environment 5.0 Update 8
Sun Java 2 Runtime Environment 5.0 Update 7
Sun Java 2 Runtime Environment 5.0 Update 6
Sun Java 2 Runtime Environment 5.0 Update 5
Sun Java 2 Runtime Environment 5.0 Update 4
Sun Java 2 Runtime Environment 5.0 Update 3
Sun Java 2 Runtime Environment 5.0 Update 2
Sun Java 2 Runtime Environment 5.0 Update 11
Sun Java 2 Runtime Environment 5.0 Update 1
Sun Java 2 Runtime Environment 5.0
IAIK XML Signature Library (IXSIL) 0
IAIK XML Security Toolkit (XSECT) 0
Gentoo Linux
BEA Systems JRockit R27.3.1
BEA Systems JRockit 6
Not Vulnerable: Sun SDK (Linux Production Release) 1.6 _02
Sun Java System Web Server 7.0 Update 1
Sun Java 2 Runtime Environment 6.0 Update 2

Discussion

Sun Java System Server XSLT Processing Remote Java Method Execution Vulnerability

Sun Java System Web Servers and Application Servers are prone to a vulnerability that lets attackers execute arbitrary Java methods. This issue occurs because the application fails to securely process XSLT stylesheets.

Successfully exploiting this issue may allow remote attackers to execute arbitrary Java methods, aiding them in further attacks.

Sun Java System Web Server 7.0 for the following operating systems is affected:
- Sun Solaris SPARC and x86 platforms
- Linux
- Microsoft Windows
- HP-UX

Sun Java System Application Server Platform and Enterprise Editions 8.2 and Platform Edition 9.0 for the following operating systems are also affected:
- Sun Solaris SPARC and x86 platforms
- Linux
- Microsoft Windows

Exploit / POC

Sun Java System Server XSLT Processing Remote Java Method Execution Vulnerability

Currently we are not aware of any working exploits for this issue. If you feel we are in error or if you are aware of more recent information, please mail us at: mailto:[email protected].

Solution / Fix

Sun Java System Server XSLT Processing Remote Java Method Execution Vulnerability

Solution:
Sun has released an advisory along with fixes to address this issue. Please see the referenced advisory for more information.


Sun Java 2 Runtime Environment 5.0 Update 6

Sun Java 2 Standard Edition SDK 5.0 Update 7

Sun Java 2 Runtime Environment 5.0 Update 1

Sun Java 2 Runtime Environment 5.0 Update 3

Sun Java System Portal Server 7

Sun Java 2 Runtime Environment 5.0.Update 12

Sun Java 2 Runtime Environment 5.0 Update 2

Sun Java 2 Standard Edition SDK 5.0 Update 3

Sun Java 2 Runtime Environment 5.0 Update 8

Sun Java 2 Standard Edition SDK 5.0 Update 2

Sun Java 2 Runtime Environment 5.0 Update 11

Sun Java 2 Runtime Environment 5.0 Update 7

Sun Java System Application Server Platform Edition 9.0 Update 1

Sun Java System Application Server Platform Edition 8.2

BEA Systems JRockit R27.3.1

Sun Java 2 Standard Edition SDK 5.0

Sun Java 2 Standard Edition SDK 5.0 Update 1

Sun Java 2 Runtime Environment 5.0

Sun Java 2 Runtime Environment 5.0.Update 10

BEA Systems JRockit 6

Sun Java 2 Standard Edition SDK 5.0 Update 8

Sun Java 2 Runtime Environment 5.0 Update 4

Sun Java 2 Standard Edition SDK 5.0 Update 9

Sun Java 2 Standard Edition SDK 5.0 Update 10

Sun Java System Application Server Platform Edition 9.0

Sun Java System Application Server Enterprise Edition 8.2

Sun Java System Web Server 7.0

Sun Java 2 Standard Edition SDK 5.0 Update 12

Sun Java 2 Runtime Environment 6.0 Update 1

Sun Java 2 Runtime Environment 5.0 Update 5

Sun Java 2 Runtime Environment 5.0.Update 9

Sun SDK (Linux Production Release) 1.5 _06

Sun SDK (Linux Production Release) 1.5 _05

Sun SDK (Linux Production Release) 1.5 _11

Sun SDK (Linux Production Release) 1.5 _04

Sun SDK (Linux Production Release) 1.6 _1

References

© CVE.report 2026

Use of this information constitutes acceptance for use in an AS IS condition. There are NO warranties, implied or otherwise, with regard to this information or its use. Any use of this information is at the user's risk. It is the responsibility of user to evaluate the accuracy, completeness or usefulness of any information, opinion, advice or other content. EACH USER WILL BE SOLELY RESPONSIBLE FOR ANY consequences of his or her direct or indirect use of this web site. ALL WARRANTIES OF ANY KIND ARE EXPRESSLY DISCLAIMED. This site will NOT BE LIABLE FOR ANY DIRECT, INDIRECT or any other kind of loss.

CVE, CWE, and OVAL are registred trademarks of The MITRE Corporation and the authoritative source of CVE content is MITRE's CVE web site. This site includes MITRE data granted under the following license.

Free CVE JSON API cve.report/api

CVE.report and Source URL Uptime Status status.cve.report