5 results (0.010 seconds)

CVSS: 4.9EPSS: 0%CPEs: 22EXPL: 0

The session failover function in Cosminexus Component Container in Cosminexus 6, 6.7, and 7 before 20070731, as used in multiple Hitachi products, can use session data for the wrong user under unspecified conditions, which might allow remote authenticated users to obtain sensitive information, corrupt another user's session data, and possibly gain privileges. La función de recuperación de sesión ante fallos en Cosminexus Component Container de Cosminexus 6, 6.7, y 7 anterior al 31/07/2007, como el usado en múltiples productos de Hitachi, puede utilizar información de la sesión para el usuario equivocado bajo ciertas condiciones no especificadas, lo cual podría permitir a usuarios autenticados remotos obtener información sensible, corromper la información de sesión de otros usuarios, y posiblemente obtener privilegios. • http://osvdb.org/37852 http://secunia.com/advisories/26250 http://www.hitachi-support.com/security_e/vuls_e/HS07-024_e/index-e.html http://www.securityfocus.com/bid/25145 http://www.vupen.com/english/advisories/2007/2725 https://exchange.xforce.ibmcloud.com/vulnerabilities/35706 •

CVSS: 6.8EPSS: 1%CPEs: 5EXPL: 0

SQL injection vulnerability in Hitachi Collaboration - Online Community Management 01-00 through 01-30, as used in Groupmax Collaboration Portal, Groupmax Collaboration Web Client, uCosminexus Collaboration Portal, Cosminexus Collaboration Portal, and uCosminexus Content Manager, allows remote attackers to execute arbitrary SQL commands via unspecified vectors. Vulnerabilidad de inyección SQL en Hitachi Collaboration - Online Community Management 01-00 hasta la 01-30, utilizado en Groupmax Collaboration Portal, Groupmax Collaboration Web Client, uCosminexus Collaboration Portal, Cosminexus Collaboration Portal, y uCosminexus Content Manager, permite a atacantes remotos ejecutar comandos SQL de su elección a través vectores no especificados. • http://osvdb.org/34544 http://secunia.com/advisories/24693 http://www.hitachi-support.com/security_e/vuls_e/HS07-008_e/index-e.html http://www.securityfocus.com/bid/23208 http://www.vupen.com/english/advisories/2007/1168 https://exchange.xforce.ibmcloud.com/vulnerabilities/33348 •

CVSS: 6.8EPSS: 2%CPEs: 9EXPL: 0

Multiple cross-site scripting (XSS) vulnerabilities in Hitachi Groupmax Collaboration Portal and Web Client before 07-20-/D, and uCosminexus Collaboration Portal and Forum/File Sharing before 06-20-/C, allow remote attackers to "execute malicious scripts" via unknown vectors (aka HS06-014-01). Múltiples vulnerabilidades de secuencia de comandos en sitios cruzados (XSS) en Hitachi Groupmax Collaboration Portal y Web Client anterior 07-20-/D, y uCosminexus Collaboration Portal y Forum/File Sharing anterior a 06-20-/C, permite a atacantes remotos "ejecutar secuencias de comandos maliciosas" a través de vectores desconocidos (también conocido como HS06-014-01). • http://secunia.com/advisories/20926 http://www.hitachi-support.com/security_e/vuls_e/HS06-014_e/01-e.html http://www.hitachi-support.com/security_e/vuls_e/HS06-014_e/index-e.html http://www.securityfocus.com/bid/18830 http://www.vupen.com/english/advisories/2006/2665 https://exchange.xforce.ibmcloud.com/vulnerabilities/27605 •

CVSS: 4.3EPSS: 0%CPEs: 6EXPL: 0

Multiple cross-site scripting (XSS) vulnerabilities in Hitachi Cosminexus Collaboration Portal 06-00 through 06-10-/B, Groupmax Collaboration Portal 07-00 through 07-10-/B, and Groupmax Collaboration Web Client 07-00 through 07-10-/A allow remote attackers to inject arbitrary web script or HTML via the (1) Schedule and (2) Calendar components. • http://secunia.com/advisories/17634 http://securitytracker.com/alerts/2005/Nov/1015241.html http://securitytracker.com/alerts/2005/Nov/1015242.html http://www.hitachi-support.com/security_e/vuls_e/HS05-023_e/01-e.html http://www.osvdb.org/20969 http://www.osvdb.org/22126 http://www.securityfocus.com/bid/15498 https://exchange.xforce.ibmcloud.com/vulnerabilities/23197 •

CVSS: 7.8EPSS: 1%CPEs: 6EXPL: 0

Unspecified vulnerability in Hitachi Cosminexus Collaboration Portal 06-00 through 06-10-/B, Groupmax Collaboration Portal 07-00 through 07-10-/B, and Groupmax Collaboration Web Client 07-00 through 07-10-/A allow remote attackers to cause a denial of service of unspecified impact via repeated invalid requests to the Schedule component. • http://secunia.com/advisories/17634 http://securitytracker.com/alerts/2005/Nov/1015241.html http://securitytracker.com/alerts/2005/Nov/1015242.html http://www.hitachi-support.com/security_e/vuls_e/HS05-023_e/01-e.html http://www.securityfocus.com/bid/15500 https://exchange.xforce.ibmcloud.com/vulnerabilities/23193 •