CVE-2007-4124: Medium severity Hitachi Cosminexus Application Server vulnerability
The session failover function in Cosminexus Component Container in Cosminexus 6, 6.7, and 7 before 20070731, as used in multiple Hitachi products, can use session data for the wrong user under unspecified conditions, which might allow remote authenticated users to obtain sensitive information, corrupt another user's session data, and possibly gain privileges.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2007-4124?
CVE-2007-4124 is classified as a medium severity vulnerability that can potentially allow unauthorized access to sensitive information.
How do I fix CVE-2007-4124?
To fix CVE-2007-4124, update to a version of Hitachi Cosminexus that addresses this vulnerability, specifically versions released after July 31, 2007.
Who is affected by CVE-2007-4124?
CVE-2007-4124 affects users of Hitachi Cosminexus versions 6, 6.7, and 7 released before July 31, 2007.
What kind of impact does CVE-2007-4124 have?
The impact of CVE-2007-4124 includes the possibility of remote authenticated users gaining access to the session data of other users.
Is there a workaround for CVE-2007-4124?
Currently, there are no known workarounds for CVE-2007-4124 other than updating to a patched version.