Vulnerability Description
Cosminexus Manager in Cosminexus Application Server 06-50 and later might assign the wrong user's group permissions to logical J2EE server processes, which allows local users to gain privileges.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Hitachi | Cosminexus Application Server Enterprise | 06_50 |
| Hitachi | Cosminexus Application Server Standard | 06_50 |
| Hitachi | Electronic Form Workflow - Standard Set | 07_00 |
| Hitachi | Electronic Form Workflow -Professional Library Set | 07_00 |
| Hitachi | Ucosminexus Application Server Enterprise | 06_70 |
| Hitachi | Ucosminexus Application Server Standard | 06_70 |
| Hitachi | Ucosminexus Service Platform | 07_00 |
Related Weaknesses (CWE)
References
- http://osvdb.org/37854
- http://secunia.com/advisories/26589PatchVendor Advisory
- http://www.hitachi-support.com/security_e/vuls_e/HS07-025_e/index-e.htmlPatch
- http://www.securityfocus.com/bid/25434Patch
- https://exchange.xforce.ibmcloud.com/vulnerabilities/36245
- http://osvdb.org/37854
- http://secunia.com/advisories/26589PatchVendor Advisory
- http://www.hitachi-support.com/security_e/vuls_e/HS07-025_e/index-e.htmlPatch
- http://www.securityfocus.com/bid/25434Patch
- https://exchange.xforce.ibmcloud.com/vulnerabilities/36245
FAQ
What is CVE-2007-4563?
CVE-2007-4563 is a vulnerability with a CVSS score of 4.4 (MEDIUM). Cosminexus Manager in Cosminexus Application Server 06-50 and later might assign the wrong user's group permissions to logical J2EE server processes, which allows local users to gain privileges.
How severe is CVE-2007-4563?
CVE-2007-4563 has been rated MEDIUM with a CVSS base score of 4.4/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2007-4563?
Check the references section above for vendor advisories and patch information. Affected products include: Hitachi Cosminexus Application Server Enterprise, Hitachi Cosminexus Application Server Standard, Hitachi Electronic Form Workflow - Standard Set, Hitachi Electronic Form Workflow -Professional Library Set, Hitachi Ucosminexus Application Server Enterprise.