2 results (0.009 seconds)

CVSS: 4.9EPSS: 0%CPEs: 22EXPL: 0

The session failover function in Cosminexus Component Container in Cosminexus 6, 6.7, and 7 before 20070731, as used in multiple Hitachi products, can use session data for the wrong user under unspecified conditions, which might allow remote authenticated users to obtain sensitive information, corrupt another user's session data, and possibly gain privileges. La función de recuperación de sesión ante fallos en Cosminexus Component Container de Cosminexus 6, 6.7, y 7 anterior al 31/07/2007, como el usado en múltiples productos de Hitachi, puede utilizar información de la sesión para el usuario equivocado bajo ciertas condiciones no especificadas, lo cual podría permitir a usuarios autenticados remotos obtener información sensible, corromper la información de sesión de otros usuarios, y posiblemente obtener privilegios. • http://osvdb.org/37852 http://secunia.com/advisories/26250 http://www.hitachi-support.com/security_e/vuls_e/HS07-024_e/index-e.html http://www.securityfocus.com/bid/25145 http://www.vupen.com/english/advisories/2007/2725 https://exchange.xforce.ibmcloud.com/vulnerabilities/35706 •

CVSS: 5.0EPSS: 0%CPEs: 20EXPL: 0

Unspecified vulnerability in Hitachi Cosminexus Component Container 07-00 through 07-00-10, and 07-10 through 07-10-03, as used in uCosminexus Application Server Enterprise and Standard; uCosminexus Service Platform; uCosminexus Developer Standard and Professional; uCosminexus Service Architect; Electronic Form Workflow Standard Set, Professional Library Set, and Developer Client Set; and uCosminexus ERP Integrator, does not properly manage session information, which has an unspecified impact related to "unintended other requests." Vulnerabilidad sin especificar en el Hitachi Cosminexus Component Container 07-00 hasta la 07-00-10 y la 07-10 hasta la 07-10-03, como la utilizada en el uCosminexus Application Server Enterprise y Standard; uCosminexus Service Platform; uCosminexus Developer Standard y Professional; uCosminexus Service Architect; Electronic Form Workflow Standard Set, Professional Library Set y Developer Client Set y uCosminexus ERP Integrator, no maneja correctamente la información de la sesión lo que tiene un impacto sin especificar sobre "otras peticiones no intencionadas". • http://osvdb.org/34768 http://secunia.com/advisories/24683 http://www.hitachi-support.com/security_e/vuls_e/HS07-006_e/index-e.html http://www.securityfocus.com/bid/23213 http://www.vupen.com/english/advisories/2007/1170 https://exchange.xforce.ibmcloud.com/vulnerabilities/33318 •