CVE-2007-4124
Last modified
CVE-2007-4124 is a vulnerability of currently unknown severity. The session failover function in Cosminexus Component Container in Cosminexus 6, 6.7, and 7 before 20070731, as used in multiple Hitachi products, can use session data for the wrong user under unspecified conditions, which might allow remote authenticated users to obtain sensitive information, corrupt another user's session data, and possibly gain privileges.. EPSS estimates a 1.01% chance of exploitation in the next 30 days.
Description
The session failover function in Cosminexus Component Container in Cosminexus 6, 6.7, and 7 before 20070731, as used in multiple Hitachi products, can use session data for the wrong user under unspecified conditions, which might allow remote authenticated users to obtain sensitive information, corrupt another user's session data, and possibly gain privileges.
Metrics
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Hitachi | Cosminexus Application Server | 6 |
| Hitachi | Cosminexus Collaboration Portal | All versions |
| Hitachi | Cosminexus Developer | 6 |
| Hitachi | Cosminexus Erp Integrator | All versions |
| Hitachi | Cosminexus Opentp1 Web Front-End Set | All versions |
| Hitachi | Electronic Form Workflow | All versions |
| Hitachi | Groupmax Collaboration Portal | All versions |
| Hitachi | Ucosminexus Application Server | All versions |
| Hitachi | Ucosminexus Collaboration Portal | All versions |
| Hitachi | Ucosminexus Developer | All versions |
| Hitachi | Ucosminexus Erp Integrator | All versions |
| Hitachi | Ucosminexus Opentp1 Web Front-End Set | All versions |
| Hitachi | Ucosminexus Service Architect | All versions |
| Hitachi | Ucosminexus Service Platform | All versions |
References
- http://secunia.com/advisories/26250Vendor Advisory
- http://www.hitachi-support.com/security_e/vuls_e/HS07-024_e/index-e.htmlPatch, Vendor Advisory
- http://secunia.com/advisories/26250Vendor Advisory
- http://www.hitachi-support.com/security_e/vuls_e/HS07-024_e/index-e.htmlPatch, Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2007-4124?
How severe is CVE-2007-4124?
How do I fix CVE-2007-4124?
Are you affected by CVE-2007-4124?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
