← Back

CVE-2008-2945

nvd nist
Published: Jun 30, 2008Modified: Apr 23, 2026

JSON object

Loading...
7.5
Vector
AV:N/AC:L/Au:N/C:P/I:P/A:P
Exploitability: 10.0 / Impact: 6.4
Source: NVD

Description

Sun Java System Access Manager 6.3 through 7.1 and Sun Java System Identity Server 6.1 and 6.2 do not properly process XSLT stylesheets in XSLT transforms in XML signatures, which allows context-dependent attackers to execute arbitrary code via a crafted stylesheet, a related issue to CVE-2007-3715, CVE-2007-3716, and CVE-2007-4289.

Affected (5)

2 products
Java System Access Manager
Java System Identity Server
Configuration A
5 vulnerable
Vulnerable SoftwareAffected Versions
Sun
Version 6.3
Version 7.0
Version 7.1
Sun
Version 6.1
Version 6.2

Timeline

No history available yet.