HIGH · 9.0

CVE-2009-1088

Hannon Hill Cascade Server 5.7 and other versions allows remote authenticated users to execute arbitrary programs or Java code via a crafted XSLT stylesheet with "extension elements and extension func...

Vulnerability Description

Hannon Hill Cascade Server 5.7 and other versions allows remote authenticated users to execute arbitrary programs or Java code via a crafted XSLT stylesheet with "extension elements and extension functions" that trigger code execution by Xalan-Java, as demonstrated using xalan://java.lang.Runtime.

CVSS Score

9.0

HIGH

AV:N/AC:L/Au:S/C:C/I:C/A:C
Confidentiality
COMPLETE
Integrity
COMPLETE
Availability
COMPLETE

Affected Products

VendorProductVersions
HannonhillCascade5.7

Related Weaknesses (CWE)

References

FAQ

What is CVE-2009-1088?

CVE-2009-1088 is a vulnerability with a CVSS score of 9.0 (HIGH). Hannon Hill Cascade Server 5.7 and other versions allows remote authenticated users to execute arbitrary programs or Java code via a crafted XSLT stylesheet with "extension elements and extension func...

How severe is CVE-2009-1088?

CVE-2009-1088 has been rated HIGH with a CVSS base score of 9.0/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2009-1088?

Check the references section above for vendor advisories and patch information. Affected products include: Hannonhill Cascade.