Skip to Main Content

Integration

Announcement

For appeals, questions and feedback about Oracle Forums, please email oracle-forums-moderators_us@oracle.com. Technical questions should be asked in the appropriate category. Thank you!

Sun ONE / Sun Java System Webserver 7.0 and related vulnerability CVE-2007-3715

9392639e-cc7b-41bb-904d-a0ea1a178280Dec 28 2015 — edited Dec 29 2015

I came to know that Sun Java web server version 7 has some vulnerability as below,

"Sun Java System Application Server and Web Server 7.0 through 9.0 before 20070710 do not properly process XSLT stylesheets in XSLT transforms in XML signatures, which allows context-dependent attackers to execute an arbitrary Java method via a crafted stylesheet, a related issue to CVE-2007-3716."


My clarification is that this vulnerability doesn't inform whether same was for only version 7 or all of its updates included. Further, was it resolved under any update within same version or has to be updated to a higher version - is also not mentioned. Since I'm not able to find any relevant document which clears this, can someone clarify on the same?

Comments
Locked Post
New comments cannot be posted to this locked post.
Post Details
Locked on Jan 26 2016
Added on Dec 28 2015
1 comment
899 views