OSVDB ID: 37852

Title: Hitachi Multiple Products Cosminexus Component Container Session Data Handling Privilege Escalation

Info

Disclosure

Jul 31, 2007

Discovery

Unknown

Dates

Exploit

Unknown

Solution

Jul 31, 2007

Description

uCosminexus Application Server contains an unspecified flaw that may allow a user to use the session data of another user. It is possible that the flaw may allow remote authenticated users to access or modify another user's data resulting in a loss of integrity.

Classification

Location: Local / Remote
Attack Type: Other
Impact: Loss of Confidentiality
Solution: Patch / RCS
Disclosure: Vendor Verified

Solution

Currently, there are no known workarounds or upgrades to correct this issue. However, Hitachi has released a patch to address this vulnerability.

Products

Unknown or Incomplete

References

Credit

Unknown or Incomplete



Direct URL: http://osvdb.org/37852