CVE-2007-4124
Last modified
CVE-2007-4124 is a vulnerability of currently unknown severity. The session failover function in Cosminexus Component Container in Cosminexus 6, 6.7, and 7 before 20070731, as used in multiple Hitachi products, can use session data for the wrong user under unspecified conditions, which might allow remote authenticated users to obtain sensitive information, corrupt another user's session data, and possibly gain privileges.. EPSS estimates a 1.01% chance of exploitation in the next 30 days.
Description
The session failover function in Cosminexus Component Container in Cosminexus 6, 6.7, and 7 before 20070731, as used in multiple Hitachi products, can use session data for the wrong user under unspecified conditions, which might allow remote authenticated users to obtain sensitive information, corrupt another user's session data, and possibly gain privileges.
Metrics
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Hitachi | Cosminexus Application Server | 6 |
| Hitachi | Cosminexus Collaboration Portal | All versions |
| Hitachi | Cosminexus Developer | 6 |
| Hitachi | Cosminexus Erp Integrator | All versions |
| Hitachi | Cosminexus Opentp1 Web Front-End Set | All versions |
| Hitachi | Electronic Form Workflow | All versions |
| Hitachi | Groupmax Collaboration Portal | All versions |
| Hitachi | Ucosminexus Application Server | All versions |
| Hitachi | Ucosminexus Collaboration Portal | All versions |
| Hitachi | Ucosminexus Developer | All versions |
| Hitachi | Ucosminexus Erp Integrator | All versions |
| Hitachi | Ucosminexus Opentp1 Web Front-End Set | All versions |
| Hitachi | Ucosminexus Service Architect | All versions |
| Hitachi | Ucosminexus Service Platform | All versions |
References
- http://secunia.com/advisories/26250Vendor Advisory
- http://www.hitachi-support.com/security_e/vuls_e/HS07-024_e/index-e.htmlPatch, Vendor Advisory
- http://secunia.com/advisories/26250Vendor Advisory
- http://www.hitachi-support.com/security_e/vuls_e/HS07-024_e/index-e.htmlPatch, Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2007-4124?
How severe is CVE-2007-4124?
How do I fix CVE-2007-4124?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2007
- CVE-2007-4118PHP remote file inclusion vulnerability in includes/function…
- CVE-2007-4119Multiple SQL injection vulnerabilities in yonetici.asp in Be…
- CVE-2007-4120Multiple PHP remote file inclusion vulnerabilities in Jelsof…
- CVE-2007-4121Multiple SQL injection vulnerabilities in admin.aspx in E-Co…
- CVE-2007-4122Unspecified vulnerability in Hitachi JP1/Cm2/Hierarchical Vi…
- CVE-2007-4123The Groupmax Scheduler_Facilities management tool in Hitachi…
- CVE-2007-4125Unspecified vulnerability in the Address and Routing Paramet…
- CVE-2007-4126Unspecified vulnerability in the dynamic tracing framework (…
- CVE-2007-4127PHP remote file inclusion vulnerability in check_entry.php i…
- CVE-2007-4128SQL injection vulnerability in index.php in the Firestorm Te…
- CVE-2007-4129CoolKey 1.1.0 allows local users to overwrite arbitrary file…
- CVE-2007-4130The Linux kernel 2.6.9 before 2.6.9-67 in Red Hat Enterprise…
Are you affected by CVE-2007-4124?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
