Unrated severityNVD Advisory· Published Jun 30, 2008· Updated Apr 23, 2026
CVE-2008-2945
CVE-2008-2945
Description
Sun Java System Access Manager 6.3 through 7.1 and Sun Java System Identity Server 6.1 and 6.2 do not properly process XSLT stylesheets in XSLT transforms in XML signatures, which allows context-dependent attackers to execute arbitrary code via a crafted stylesheet, a related issue to CVE-2007-3715, CVE-2007-3716, and CVE-2007-4289.
Affected products
5cpe:2.3:a:sun:java_system_access_manager:6.3:*:*:*:*:*:*:*+ 2 more
- cpe:2.3:a:sun:java_system_access_manager:6.3:*:*:*:*:*:*:*
- cpe:2.3:a:sun:java_system_access_manager:7.0:*:*:*:*:*:*:*
- cpe:2.3:a:sun:java_system_access_manager:7.1:*:*:*:*:*:*:*
cpe:2.3:a:sun:java_system_identity_server:6.1:*:*:*:*:*:*:*+ 1 more
- cpe:2.3:a:sun:java_system_identity_server:6.1:*:*:*:*:*:*:*
- cpe:2.3:a:sun:java_system_identity_server:6.2:*:*:*:*:*:*:*
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
7News mentions
0No linked articles in our index yet.