First published: Wed Aug 08 2007(Updated: )
Hitachi Groupmax Collaboration - Schedule, as used in Groupmax Collaboration Portal 07-32 through 07-32-/B, uCosminexus Collaboration Portal 06-32 through 06-32-/B, and Groupmax Collaboration Web Client - Mail/Schedule 07-32 through 07-32-/A, can assign schedule data to the wrong user under unspecified conditions, which might allow remote authenticated users to obtain sensitive information.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Hitachi uCosminexus Collaboration Portal | =06-32 | |
Hitachi Groupmax Collaboration Web Client | =07-32_a | |
Hitachi Groupmax collaboration | =07-32_b | |
Hitachi uCosminexus Collaboration Portal | =06-32_b | |
Hitachi Groupmax collaboration | =07-32 | |
Hitachi Groupmax Collaboration Web Client | =07-32 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2007-4204 is classified as medium risk due to its potential impact on user data integrity.
To fix CVE-2007-4204, users should apply the latest security patches provided by Hitachi for the affected Groupmax and uCosminexus products.
CVE-2007-4204 affects Hitachi Groupmax Collaboration Portal versions 07-32 and grouped Web Client versions 07-32, as well as uCosminexus versions 06-32.
The potential consequences of CVE-2007-4204 include unauthorized access to schedule data, leading to privacy breaches and data misallocation.
While a permanent fix is recommended, temporarily limiting user permissions may help mitigate the risks associated with CVE-2007-4204 until patches are applied.