5

CVE-2007-5810

Hitachi Web Server 01-00 through 03-00-01, as used by certain Cosminexus products, does not properly validate SSL client certificates, which might allow remote attackers to spoof authentication via a client certificate with a forged signature.

Daten sind bereitgestellt durch National Vulnerability Database (NVD)
HitachiCosminexus Server Version <= 04_01
HitachiUcosminexus Developer Light Version <= 06_71_d
HitachiUcosminexus Developer Standard Version <= 07_50_01
HitachiUcosminexus Service Architect Version <= 07_50_01
HitachiUcosminexus Service Platform Version <= 07_50_01
HitachiWeb Server Version01_00 Editionhpux
HitachiWeb Server Version01_00 Editionsolaris
HitachiWeb Server Version01_01 Editionaix
HitachiWeb Server Version01_01 Editionlinux
HitachiWeb Server Version01_01 Editionturbolinux
HitachiWeb Server Version01_01_d Editionlinux
HitachiWeb Server Version01_02_d Editionhpux
HitachiWeb Server Version01_02_d Editionsolaris
HitachiWeb Server Version01_02_e Editionaix
HitachiWeb Server Version02_00 Editionaix
HitachiWeb Server Version02_00 Editionhpux
HitachiWeb Server Version02_00 Editionlinux
HitachiWeb Server Version02_00 Editionsolaris
HitachiWeb Server Version02_00 Editionturbolinux
HitachiWeb Server Version02_00 Editionwindows
HitachiWeb Server Version02_00_a Editionlinux
HitachiWeb Server Version02_02 Editionhpux
HitachiWeb Server Version02_02 Editionlinux
HitachiWeb Server Version02_04_b Editionaix
HitachiWeb Server Version02_04_b Editionhpux
HitachiWeb Server Version02_04_b Editionsolaris
HitachiWeb Server Version02_04_b Editionwindows
HitachiWeb Server Version02_06_a Editionlinux
HitachiWeb Server Version03_00 Editionaix
HitachiWeb Server Version03_00 Editionlinux
HitachiWeb Server Version03_00 Editionwindows
HitachiWeb Server Version03_00_01 Editionsolaris
HitachiWeb Server Version03_00_01 Editionwindows
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.22% 0.411
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 5 10 2.9
AV:N/AC:L/Au:N/C:N/I:P/A:N
CWE-20 Improper Input Validation

The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.