First published: Wed Aug 01 2007(Updated: )
The session failover function in Cosminexus Component Container in Cosminexus 6, 6.7, and 7 before 20070731, as used in multiple Hitachi products, can use session data for the wrong user under unspecified conditions, which might allow remote authenticated users to obtain sensitive information, corrupt another user's session data, and possibly gain privileges.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Hitachi Ucosminexus Collaboration Portal | ||
Hitachi Cosminexus Opentp1 Web Front-end Set | ||
Hitachi Ucosminexus Erp Integrator | ||
Hitachi Cosminexus Developer | =6 | |
Hitachi Ucosminexus Application Server | ||
Hitachi Ucosminexus Service Platform | ||
Hitachi Ucosminexus Developer | ||
Hitachi Electronic Form Workflow | ||
Hitachi Cosminexus Application Server | =6 | |
Hitachi Ucosminexus Opentp1 Web Front-end Set | ||
Hitachi Ucosminexus Application Server | ||
Hitachi Cosminexus Developer | =6 | |
Hitachi Ucosminexus Developer | ||
Hitachi Ucosminexus Developer | ||
Hitachi Cosminexus Application Server | =6 | |
Hitachi Cosminexus Developer | =6 | |
Hitachi Cosminexus Erp Integrator | ||
Hitachi Cosminexus Collaboration Portal | ||
Hitachi Groupmax Collaboration Portal | ||
Hitachi Electronic Form Workflow | ||
Hitachi Ucosminexus Service Architect | ||
Hitachi Electronic Form Workflow |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.