3 results (0.004 seconds)

CVSS: 5.9EPSS: 0%CPEs: 574EXPL: 0

The Fujitsu TLS library allows a man-in-the-middle attack. This affects Interstage Application Development Cycle Manager V10 and other versions, Interstage Application Server V12 and other versions, Interstage Business Application Manager V2 and other versions, Interstage Information Integrator V11 and other versions, Interstage Job Workload Server V8, Interstage List Works V10 and other versions, Interstage Studio V12 and other versions, Interstage Web Server Express V11, Linkexpress V5, Safeauthor V3, ServerView Resource Orchestrator V3, Systemwalker Cloud Business Service Management V1, Systemwalker Desktop Keeper V15, Systemwalker Desktop Patrol V15, Systemwalker IT Change Manager V14, Systemwalker Operation Manager V16 and other versions, Systemwalker Runbook Automation V15 and other versions, Systemwalker Security Control V1, and Systemwalker Software Configuration Manager V15. La biblioteca Fujitsu TLS permite un ataque de tipo man-in-the-middle. Esto afecta a Interstage Application Development Cycle Manager versión V10 y otras versiones, Interstage Application Server versión V12 y otras versiones, Interstage Business Application Manager versión V2 y otras versiones, Interstage Information Integrator versión V11 y otras versiones, Interstage Job Workload Server versión V8, Interstage List Works versión V10 y otras versiones , Interstage Studio versión V12 y otras versiones, Interstage Web Server Express versión V11, Linkexpress versión V5, Safeauthor versión V3, ServerView Resource Orchestrator versión V3, Systemwalker Cloud Business Service Management versión V1, Systemwalker Desktop Keeper versión V15, Systemwalker Desktop Patrol versión V15, Systemwalker IT Change Manager versión V14, Systemwalker Operation Manager versión V16 y otras versiones, Systemwalker Runbook Automation versión V15 y otras versiones, Systemwalker Security Control versión V1 y Systemwalker Software Configuration Manager versión V15. • https://www.fujitsu.com/jp/products/software/resources/condition/security/products-fujitsu/solution/interstage-systemwalker-tls-202001.html • CWE-326: Inadequate Encryption Strength •

CVSS: 6.4EPSS: 0%CPEs: 19EXPL: 0

Unspecified vulnerability in the Servlet service in Fujitsu Limited Interstage Application Server 3.0 through 7.0, as used in Interstage Application Framework Suite, Interstage Business Application Server, and Interstage List Manager, allows attackers to obtain sensitive information or force invalid requests to be processed via unknown vectors related to unspecified invalid requests and settings on the load balancing device. Vulnerabilidad sin especificar en el servicio Servlet en Fujitsu Limited Interstage Application Server v3.0 hasta v7.0, como el usado en Interstage Application Framework Suite, Interstage Business Application Server y Interstage List Manager, permite a atacantes obtener información sensible o forzar peticiones no válidas para ser procesadas a través de vectores desconocidos relacionados con peticiones no válidas sin especificar y características en el dispositivo de balanceo de carga. • http://jvn.jp/en/jp/JVN90248889/index.html http://jvndb.jvn.jp/ja/contents/2010/JVNDB-2010-000018.html http://osvdb.org/64703 http://secunia.com/advisories/39803 http://software.fujitsu.com/jp/security/vulnerabilities/jvn-90248889.html http://www.fujitsu.com/global/support/software/security/products-f/interstage-201001e.html http://www.securityfocus.com/bid/40189 http://www.vupen.com/english/advisories/2010/1165 https://exchange.xforce.ibmcloud.com/vulnerabilities/58634 •

CVSS: 4.3EPSS: 1%CPEs: 20EXPL: 0

Cross-site scripting (XSS) vulnerability in the Servlet Service in Fujitsu Interstage Application Server (IJServer) 8.0.2 and earlier allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, possibly involving web.xml and HTTP 404 and 500 status codes. Vulnerabilidad de secuencias de comandos en sitios cruzados (XSS) en el Servicio Servlet de Fujitsu interstage Application Server (IJServer) 8.0.2 y anteriores permite a atacantes remotos inyectar secuencias de comandos web o HTML de su elección a través de vectores no especificados, posiblemente relacionados con web.xml y códigos de estado HTTP 404 y 500. • http://jvn.jp/jp/JVN%2383832818/index.html http://osvdb.org/34276 http://secunia.com/advisories/24508 http://software.fujitsu.com/jp/security/vulnerabilities/jvn-83832818.html http://www.fujitsu.com/global/support/software/security/products-f/interstage-200701e.html http://www.securityfocus.com/bid/23020 http://www.vupen.com/english/advisories/2007/0996 https://exchange.xforce.ibmcloud.com/vulnerabilities/33099 •