4.9
CVE-2007-4124
- EPSS 0.36%
- Published 01.08.2007 16:17:00
- Last modified 09.04.2025 00:30:58
- Source cve@mitre.org
- Teams watchlist Login
- Open Login
The session failover function in Cosminexus Component Container in Cosminexus 6, 6.7, and 7 before 20070731, as used in multiple Hitachi products, can use session data for the wrong user under unspecified conditions, which might allow remote authenticated users to obtain sensitive information, corrupt another user's session data, and possibly gain privileges.
Data is provided by the National Vulnerability Database (NVD)
Hitachi ≫ Cosminexus Application Server Version6 Editionenterprise
Hitachi ≫ Cosminexus Application Server Version6 Editionstandard
Hitachi ≫ Cosminexus Developer Version6 Editionlight
Hitachi ≫ Cosminexus Developer Version6 Editionprofessional
Hitachi ≫ Cosminexus Developer Version6 Editionstandard
Hitachi ≫ Electronic Form Workflow Editiondeveloper_client_set
Hitachi ≫ Electronic Form Workflow Editionprofessional_library_set
Hitachi ≫ Electronic Form Workflow Editionstandard_set
Hitachi ≫ Groupmax Collaboration Portal Editionserver
Hitachi ≫ Ucosminexus Application Server Editionenterprise
Hitachi ≫ Ucosminexus Application Server Editionstandard
Hitachi ≫ Ucosminexus Collaboration Portal Editionserver
Hitachi ≫ Ucosminexus Developer Editionlight
Hitachi ≫ Ucosminexus Developer Editionprofessional
Hitachi ≫ Ucosminexus Developer Editionstandard
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
Type | Source | Score | Percentile |
---|---|---|---|
EPSS | FIRST.org | 0.36% | 0.554 |
Source | Base Score | Exploit Score | Impact Score | Vector string |
---|---|---|---|---|
nvd@nist.gov | 4.9 | 6.8 | 4.9 |
AV:N/AC:M/Au:S/C:P/I:P/A:N
|