CWE
NVD-CWE-Other
Advisory Published
Updated

CVE-2007-4124

First published: Wed Aug 01 2007(Updated: )

The session failover function in Cosminexus Component Container in Cosminexus 6, 6.7, and 7 before 20070731, as used in multiple Hitachi products, can use session data for the wrong user under unspecified conditions, which might allow remote authenticated users to obtain sensitive information, corrupt another user's session data, and possibly gain privileges.

Credit: cve@mitre.org

Affected SoftwareAffected VersionHow to fix
Hitachi Ucosminexus Collaboration Portal
Hitachi Cosminexus Opentp1 Web Front-end Set
Hitachi Ucosminexus Erp Integrator
Hitachi Cosminexus Developer=6
Hitachi Ucosminexus Application Server
Hitachi Ucosminexus Service Platform
Hitachi Ucosminexus Developer
Hitachi Electronic Form Workflow
Hitachi Cosminexus Application Server=6
Hitachi Ucosminexus Opentp1 Web Front-end Set
Hitachi Ucosminexus Application Server
Hitachi Cosminexus Developer=6
Hitachi Ucosminexus Developer
Hitachi Ucosminexus Developer
Hitachi Cosminexus Application Server=6
Hitachi Cosminexus Developer=6
Hitachi Cosminexus Erp Integrator
Hitachi Cosminexus Collaboration Portal
Hitachi Groupmax Collaboration Portal
Hitachi Electronic Form Workflow
Hitachi Ucosminexus Service Architect
Hitachi Electronic Form Workflow

Never miss a vulnerability like this again

Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2025 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203