CVE-2007-4575: Code Injection

Published Sep 21, 2007
·
Updated

HSQLDB before 1.8.0.9, as used in OpenOffice.org (OOo) 2 before 2.3.1, allows user-assisted remote attackers to execute arbitrary Java code via crafted database documents, related to "exposing static java methods."

Other sources

OpenOffice.org-base allows to execute arbitrary static public java methods. This can be misused by a remote attacker to send a victim a handcrafted odb files. The odb file execute these commands in the database bootstrap phase. Furthermore an unprivileged user can extend his privileges by using aliased methods.

Red Hat

Affected Software

36 affected componentsFixes available
redhat/hibernate3<1:3.2.4-1.SP1_CP02.0jpp.ep1.1.el4
1:3.2.4-1.SP1_CP02.0jpp.ep1.1.el4
redhat/hibernate3-annotations<0:3.2.1-1.patch02.1jpp.ep1.2.el4
0:3.2.1-1.patch02.1jpp.ep1.2.el4
redhat/hibernate3-entitymanager<0:3.2.1-1jpp.ep1.6.el4
0:3.2.1-1jpp.ep1.6.el4
redhat/jboss-aop<0:1.5.5-1.CP01.0jpp.ep1.1.el4
0:1.5.5-1.CP01.0jpp.ep1.1.el4
redhat/jbossas<0:4.2.0-3.GA_CP02.ep1.3.el4
0:4.2.0-3.GA_CP02.ep1.3.el4
redhat/jboss-cache<0:1.4.1-4.SP8_CP01.1jpp.ep1.1.el4
0:1.4.1-4.SP8_CP01.1jpp.ep1.1.el4
redhat/jboss-seam<0:1.2.1-1.ep1.3.el4
0:1.2.1-1.ep1.3.el4
redhat/jbossws-jboss42<0:1.2.1-0jpp.ep1.2.el4
0:1.2.1-0jpp.ep1.2.el4
redhat/jcommon<0:1.0.12-1jpp.ep1.2.el4
0:1.0.12-1jpp.ep1.2.el4
redhat/jfreechart<0:1.0.9-1jpp.ep1.2.el4
0:1.0.9-1jpp.ep1.2.el4
redhat/rh-eap-docs<0:4.2.0-3.GA_CP02.ep1.1.el4
0:4.2.0-3.GA_CP02.ep1.1.el4
redhat/hibernate3<0:3.2.4-1.SP1_CP02.0jpp.ep1.1.el5.1
0:3.2.4-1.SP1_CP02.0jpp.ep1.1.el5.1
redhat/hibernate3-annotations<0:3.2.1-1.patch02.1jpp.ep1.2.el5.1
0:3.2.1-1.patch02.1jpp.ep1.2.el5.1
redhat/jacorb<0:2.3.0-1jpp.ep1.5.el5
0:2.3.0-1jpp.ep1.5.el5
redhat/jboss-aop<0:1.5.5-1.CP01.0jpp.ep1.1.el5
0:1.5.5-1.CP01.0jpp.ep1.1.el5
redhat/jbossas<0:4.2.0-4.GA_CP02.ep1.3.el5.3
0:4.2.0-4.GA_CP02.ep1.3.el5.3
redhat/jboss-cache<0:1.4.1-4.SP8_CP01.1jpp.ep1.1.el5
0:1.4.1-4.SP8_CP01.1jpp.ep1.1.el5
redhat/jboss-remoting<0:2.2.2-3.SP4.0jpp.ep1.1.el5
0:2.2.2-3.SP4.0jpp.ep1.1.el5
redhat/jboss-seam<0:1.2.1-1.ep1.3.el5
0:1.2.1-1.ep1.3.el5
redhat/jbossweb<0:2.0.0-3.CP05.0jpp.ep1.1.el5
0:2.0.0-3.CP05.0jpp.ep1.1.el5
redhat/jcommon<0:1.0.12-1jpp.ep1.2.el5
0:1.0.12-1jpp.ep1.2.el5
redhat/jfreechart<0:1.0.9-1jpp.ep1.2.el5.1
0:1.0.9-1jpp.ep1.2.el5.1
redhat/rh-eap-docs<0:4.2.0-3.GA_CP02.ep1.1.el5.1
0:4.2.0-3.GA_CP02.ep1.1.el5.1
redhat/concurrent<0:1.3.4-7jpp.ep1.6.el4
0:1.3.4-7jpp.ep1.6.el4
redhat/glassfish-jaf<0:1.1.0-0jpp.ep1.10.el4
0:1.1.0-0jpp.ep1.10.el4
redhat/jbossxb<0:1.0.0-2.SP1.0jpp.ep1.2.el4
0:1.0.0-2.SP1.0jpp.ep1.2.el4
OpenOffice OpenOffice=2.1
OpenOffice OpenOffice=2.2
OpenOffice OpenOffice=2.0.3_1
OpenOffice OpenOffice=2.2.1
OpenOffice OpenOffice=2.0.4
OpenOffice OpenOffice<=2.3
OpenOffice OpenOffice=2.0.3
OpenOffice OpenOffice=2.0beta
OpenOffice OpenOffice=2.0.1
OpenOffice OpenOffice=2.0.2

Event History

Sep 21, 2007
Data Sourced
via Red Hat·08:03 AM
DescriptionSeverityAffected Software
Dec 4, 2007
CVE Published
via Red Hat·12:00 AM
Dec 6, 2007
CVE Published
via MITRE·07:00 AM
Data Sourced
via MITRE·07:00 AM
Description

Parent advisories

This vulnerability appears in the following advisories.

Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the severity of CVE-2007-4575?

CVE-2007-4575 has been rated as having a moderate severity level due to its potential to allow arbitrary code execution.

2

How do I fix CVE-2007-4575?

To mitigate CVE-2007-4575, upgrade HSQLDB to version 1.8.0.9 or later which addresses the code execution vulnerability.

3

Which software is affected by CVE-2007-4575?

CVE-2007-4575 affects versions of OpenOffice.org before 2.3.1 that utilize HSQLDB before version 1.8.0.9.

4

What types of attacks can CVE-2007-4575 enable?

CVE-2007-4575 can enable user-assisted remote attackers to execute arbitrary Java code through specially crafted database documents.

5

Is CVE-2007-4575 related to Java code execution risks?

Yes, CVE-2007-4575 specifically involves the exposure of static Java methods that facilitate the execution of arbitrary Java code.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203