Vulnerability Description
The Javadoc tool in Sun JDK 6 and JDK 5.0 Update 11 can generate HTML documentation pages that contain cross-site scripting (XSS) vulnerabilities, which allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Oracle | Jdk | 1.5.0 |
Related Weaknesses (CWE)
References
- http://dev2dev.bea.com/pub/advisory/248Third Party Advisory
- http://docs.info.apple.com/article.html?artnum=307177Third Party Advisory
- http://lists.apple.com/archives/Security-announce/2007/Dec/msg00001.htmlMailing ListThird Party Advisory
- http://osvdb.org/36488Broken Link
- http://secunia.com/advisories/25769Third Party Advisory
- http://secunia.com/advisories/26314Third Party Advisory
- http://secunia.com/advisories/26369Third Party Advisory
- http://secunia.com/advisories/26631Third Party Advisory
- http://secunia.com/advisories/26645Third Party Advisory
- http://secunia.com/advisories/26933Third Party Advisory
- http://secunia.com/advisories/27203Third Party Advisory
- http://secunia.com/advisories/28115Third Party Advisory
- http://sunsolve.sun.com/search/document.do?assetkey=1-26-102958-1Broken Link
- http://www.gentoo.org/security/en/glsa/glsa-200709-15.xmlThird Party Advisory
- http://www.redhat.com/support/errata/RHSA-2007-0818.htmlThird Party Advisory
FAQ
What is CVE-2007-3503?
CVE-2007-3503 is a vulnerability with a CVSS score of 4.3 (MEDIUM). The Javadoc tool in Sun JDK 6 and JDK 5.0 Update 11 can generate HTML documentation pages that contain cross-site scripting (XSS) vulnerabilities, which allows remote attackers to inject arbitrary web...
How severe is CVE-2007-3503?
CVE-2007-3503 has been rated MEDIUM with a CVSS base score of 4.3/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2007-3503?
Check the references section above for vendor advisories and patch information. Affected products include: Oracle Jdk.