CVE-2007-4289: Medium severity Sun Java System Portal Server vulnerability
Published Aug 9, 2007
·Updated
Sun Java System Portal Server 7.0 does not properly process XSLT stylesheets in XSLT transforms in XML signatures, which allows context-dependent attackers to execute an arbitrary Java method via a crafted stylesheet, a related issue to CVE-2007-3715.
Affected Software
1 affected component
Sun Java System Portal Server=7.0
Remediation
Patch Available
Event History
Aug 9, 2007
CVE Published
09:17 PM
Aug 10, 2007
CVE Published
via MITRE·01:00 AM
Data Sourced
via MITRE·01:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2007-4289?
CVE-2007-4289 has a medium severity rating as it allows context-dependent attackers to execute arbitrary Java methods.
2
How do I fix CVE-2007-4289?
To fix CVE-2007-4289, update Sun Java System Portal Server to the latest patched version.
3
What software is affected by CVE-2007-4289?
CVE-2007-4289 specifically affects Sun Java System Portal Server version 7.0.
4
What type of attack is associated with CVE-2007-4289?
CVE-2007-4289 is associated with command injection attacks via crafted XSLT stylesheets.
5
Can CVE-2007-4289 allow remote code execution?
Yes, CVE-2007-4289 can potentially allow remote code execution by exploiting malformed XML signatures.