CVE-2007-2904: XSS
Cross-site scripting (XSS) vulnerability in Sun Java System Messaging Server 6.0 through 6.3, when Internet Explorer is used, allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, possibly a related issue to CVE-2006-5653.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2007-2904?
The severity of CVE-2007-2904 is considered to be high due to the potential for attackers to exploit the XSS vulnerability.
How do I fix CVE-2007-2904?
To fix CVE-2007-2904, it is recommended to upgrade Sun Java System Messaging Server to a version that is not affected, ideally to version 6.4 or later.
Who is affected by CVE-2007-2904?
CVE-2007-2904 affects users of Sun Java System Messaging Server versions 6.0 to 6.3 using Internet Explorer.
What kind of attacks can CVE-2007-2904 facilitate?
CVE-2007-2904 can facilitate cross-site scripting (XSS) attacks, allowing attackers to inject malicious scripts into web pages viewed by users.
Is there a workaround for CVE-2007-2904?
While upgrading is the best option, a temporary workaround may include disabling or limiting the use of Internet Explorer for accessing the affected services.