This CPE summary could be partial or incomplete. Please contact us for a detailed listing.

Summary

Detail
Vendor Hitachi First view 2007-08-27
Product Ucosminexus Application Server Enterprise Last view 2007-11-05
Version 07_10 Type Application
Update *  
Edition hpux  
Language *  
Sofware Edition *  
Target Software *  
Target Hardware *  
Other *  
 
CPE Product cpe:2.3:a:hitachi:ucosminexus_application_server_enterprise

Activity : Overall

Related : CVE

  Date Alert Description
5 2007-11-05 CVE-2007-5810

Hitachi Web Server 01-00 through 03-00-01, as used by certain Cosminexus products, does not properly validate SSL client certificates, which might allow remote attackers to spoof authentication via a client certificate with a forged signature.

4.3 2007-11-05 CVE-2007-5809

Cross-site scripting (XSS) vulnerability in Hitachi Web Server 01-00 through 03-10, as used by certain Cosminexus products, allows remote attackers to inject arbitrary web script or HTML via unspecified HTTP requests that trigger creation of a server-status page.

4.3 2007-09-08 CVE-2007-4760

The javadoc tool in Cosminexus Developer's Kit for Java in Cosminexus 7 and 7.5 can generate HTML documents that contain cross-site scripting (XSS) vulnerabilities, which allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. NOTE: this is probably the same issue as CVE-2007-3503.

5 2007-09-08 CVE-2007-4759

Multiple unspecified vulnerabilities in the image-processing APIs in Cosminexus Developer's Kit for Java in Cosminexus 4 through 7 allow remote attackers to cause a denial of service via unspecified vectors.

10 2007-09-08 CVE-2007-4758

Multiple buffer overflows in the image-processing APIs in Cosminexus Developer's Kit for Java in Cosminexus 4 through 7 allow remote attackers to cause a denial of service or execute arbitrary code via unspecified vectors.

4.6 2007-08-27 CVE-2007-4564

Cosminexus Manager in Cosminexus Application Server 07-00 and later might assign the wrong user's group permissions to logical user server processes, which allows local users to gain privileges.

4.4 2007-08-27 CVE-2007-4563

Cosminexus Manager in Cosminexus Application Server 06-50 and later might assign the wrong user's group permissions to logical J2EE server processes, which allows local users to gain privileges.

CWE : Common Weakness Enumeration

%idName
28% (2) CWE-264 Permissions, Privileges, and Access Controls
28% (2) CWE-119 Failure to Constrain Operations within the Bounds of a Memory Buffer
28% (2) CWE-79 Failure to Preserve Web Page Structure ('Cross-site Scripting')
14% (1) CWE-20 Improper Input Validation

Open Source Vulnerability Database (OSVDB)

id Description
42027 Hitachi Web Server Server-status Page Creation Unspecified XSS
42026 Hitachi Web Server SSL Client Certification Validation Weakness
37858 Hitachi Cosminexus Developer's Kit for Java Multiple Unspecified DoS
37857 Hitachi Cosminexus Developer's Kit for Java Multiple Unspecified Overflows
37855 Hitachi Cosminexus Application Server Manager Logical User Server Process Per...
37854 Hitachi Cosminexus Application Server Manager Logical J2EE Server Process Per...
36781 Hitachi Cosminexus Products javadoc Tool Unspecified XSS