Vulnerability Description
Hannon Hill Cascade Server 5.7 and other versions allows remote authenticated users to execute arbitrary programs or Java code via a crafted XSLT stylesheet with "extension elements and extension functions" that trigger code execution by Xalan-Java, as demonstrated using xalan://java.lang.Runtime.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Hannonhill | Cascade | 5.7 |
Related Weaknesses (CWE)
References
- http://support.hannonhill.com/browse/CSCD-4753
- http://www.securityfocus.com/archive/1/501981/100/0/threaded
- http://www.securityfocus.com/bid/34186
- https://exchange.xforce.ibmcloud.com/vulnerabilities/49332
- https://www.exploit-db.com/exploits/8247
- http://support.hannonhill.com/browse/CSCD-4753
- http://www.securityfocus.com/archive/1/501981/100/0/threaded
- http://www.securityfocus.com/bid/34186
- https://exchange.xforce.ibmcloud.com/vulnerabilities/49332
- https://www.exploit-db.com/exploits/8247
FAQ
What is CVE-2009-1088?
CVE-2009-1088 is a vulnerability with a CVSS score of 9.0 (HIGH). Hannon Hill Cascade Server 5.7 and other versions allows remote authenticated users to execute arbitrary programs or Java code via a crafted XSLT stylesheet with "extension elements and extension func...
How severe is CVE-2009-1088?
CVE-2009-1088 has been rated HIGH with a CVSS base score of 9.0/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2009-1088?
Check the references section above for vendor advisories and patch information. Affected products include: Hannonhill Cascade.