CVE-2007-5808
https://notcve.org/view.php?id=CVE-2007-5808
Unspecified vulnerability in the Groupmax Collaboration - Schedule component in Hitachi Groupmax Collaboration Portal 07-30 through 07-30-/F and 07-32 through 07-32-/C, uCosminexus Collaboration Portal 06-30 through 06-30-/F and 06-32 through 06-32-/C, and Groupmax Collaboration Web Client - Mail/Schedule 07-30 through 07-30-/F and 07-32 through 07-32-/B might allow remote attackers to obtain sensitive information via unspecified vectors related to schedule portlets. Vulnerabilidad no especificada en el componente Groupmax Collaboration - Schedule de Hitachi Groupmax Collaboration Portal 07-30 hasta 07-30-/F y 07-32 hasta 07-32-/C, uCosminexus Collaboration Portal 06-30 hasta 06-30-/F y 06-32 hasta 06-32-/C, y Groupmax Collaboration Web Client - Mail/Schedule 07-30 hasta 07-30-/F y d 07-32 hasta 07-32-/B podría permitir a atacantes remotos obtener información confidencial mediante vectores no especificados relativos a portlets de agenda. • http://osvdb.org/42025 http://secunia.com/advisories/27451 http://www.hitachi-support.com/security_e/vuls_e/HS07-036_e/index-e.html http://www.securityfocus.com/bid/26272 http://www.vupen.com/english/advisories/2007/3667 https://exchange.xforce.ibmcloud.com/vulnerabilities/38188 •
CVE-2007-4204
https://notcve.org/view.php?id=CVE-2007-4204
Hitachi Groupmax Collaboration - Schedule, as used in Groupmax Collaboration Portal 07-32 through 07-32-/B, uCosminexus Collaboration Portal 06-32 through 06-32-/B, and Groupmax Collaboration Web Client - Mail/Schedule 07-32 through 07-32-/A, can assign schedule data to the wrong user under unspecified conditions, which might allow remote authenticated users to obtain sensitive information. Hitachi Groupmax Collaboration - Schedule, usado en Groupmax Collaboration Portal 07-32 hasta 07-32-/B, uCosminexus Collaboration Portal 06-32 hasta 06-32-/B, y Groupmax Collaboration Web Client - Mail/Schedule 07-32 hasta 07-32-/A, puede asignar datos de programación (schedule) al usuario incorrecto bajo condiciones no especificadas, lo cual podría permitir a usuarios autenticados remotamente obtener información sensible. • http://osvdb.org/46987 http://www.hitachi-support.com/security_e/vuls_e/HS07-022_e/index-e.html http://www.vupen.com/english/advisories/2007/2723 https://exchange.xforce.ibmcloud.com/vulnerabilities/35704 •
CVE-2007-4124
https://notcve.org/view.php?id=CVE-2007-4124
The session failover function in Cosminexus Component Container in Cosminexus 6, 6.7, and 7 before 20070731, as used in multiple Hitachi products, can use session data for the wrong user under unspecified conditions, which might allow remote authenticated users to obtain sensitive information, corrupt another user's session data, and possibly gain privileges. La función de recuperación de sesión ante fallos en Cosminexus Component Container de Cosminexus 6, 6.7, y 7 anterior al 31/07/2007, como el usado en múltiples productos de Hitachi, puede utilizar información de la sesión para el usuario equivocado bajo ciertas condiciones no especificadas, lo cual podría permitir a usuarios autenticados remotos obtener información sensible, corromper la información de sesión de otros usuarios, y posiblemente obtener privilegios. • http://osvdb.org/37852 http://secunia.com/advisories/26250 http://www.hitachi-support.com/security_e/vuls_e/HS07-024_e/index-e.html http://www.securityfocus.com/bid/25145 http://www.vupen.com/english/advisories/2007/2725 https://exchange.xforce.ibmcloud.com/vulnerabilities/35706 •
CVE-2007-3043
https://notcve.org/view.php?id=CVE-2007-3043
Cross-site scripting (XSS) vulnerability in Collaboration - File Sharing 01-20 up to 01-20-/B and 01-30 up to 01-30-/B in Hitachi Groupmax Collaboration Portal up to 07-30-/D, Groupmax Collaboration Web Client - Forum/File Sharing up to 07-30-/C, uCosminexus Collaboration Portal up to 06-30-/D, and uCosminexus Collaboration Portal - Forum/File Sharing up to 06-30-/C on Windows allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. Vulnerabilidad de secuencias de comandos en sitios cruzados (XSS) en Collaboration - File Sharing 01-20 hasta 01-20-/B y 01-30 hasta 01-30-/B en Hitechi Groupmax Collaboration Portal hasta 07-30-/D, Groupmax Collaboration Web Client - Forum/File Sharing hasta 07-30-/C, uCosminexus Collaboration Portal hasta 06-30-/D, y uCosminexus Collaboration Portal - Forum/File Sharing hasta 06-30-/C en Windows permite a atacantes remotos inyectar secuencias de comandos web o HTML de su elección a través de vectores no especificados. • http://osvdb.org/36828 http://secunia.com/advisories/25507 http://www.hitachi-support.com/security_e/vuls_e/HS07-011_e/index-e.html http://www.securityfocus.com/bid/24263 http://www.vupen.com/english/advisories/2007/2020 https://exchange.xforce.ibmcloud.com/vulnerabilities/34659 •
CVE-2007-1786
https://notcve.org/view.php?id=CVE-2007-1786
SQL injection vulnerability in Hitachi Collaboration - Online Community Management 01-00 through 01-30, as used in Groupmax Collaboration Portal, Groupmax Collaboration Web Client, uCosminexus Collaboration Portal, Cosminexus Collaboration Portal, and uCosminexus Content Manager, allows remote attackers to execute arbitrary SQL commands via unspecified vectors. Vulnerabilidad de inyección SQL en Hitachi Collaboration - Online Community Management 01-00 hasta la 01-30, utilizado en Groupmax Collaboration Portal, Groupmax Collaboration Web Client, uCosminexus Collaboration Portal, Cosminexus Collaboration Portal, y uCosminexus Content Manager, permite a atacantes remotos ejecutar comandos SQL de su elección a través vectores no especificados. • http://osvdb.org/34544 http://secunia.com/advisories/24693 http://www.hitachi-support.com/security_e/vuls_e/HS07-008_e/index-e.html http://www.securityfocus.com/bid/23208 http://www.vupen.com/english/advisories/2007/1168 https://exchange.xforce.ibmcloud.com/vulnerabilities/33348 •