MEDIUM · 4.3

CVE-2007-5809

Cross-site scripting (XSS) vulnerability in Hitachi Web Server 01-00 through 03-10, as used by certain Cosminexus products, allows remote attackers to inject arbitrary web script or HTML via unspecifi...

Vulnerability Description

Cross-site scripting (XSS) vulnerability in Hitachi Web Server 01-00 through 03-10, as used by certain Cosminexus products, allows remote attackers to inject arbitrary web script or HTML via unspecified HTTP requests that trigger creation of a server-status page.

CVSS Score

4.3

MEDIUM

AV:N/AC:M/Au:N/C:N/I:P/A:N
Confidentiality
NONE
Integrity
PARTIAL
Availability
NONE

Affected Products

VendorProductVersions
HitachiCosminexus Application Server Enterprise<= 06_51_j
HitachiCosminexus Application Server Standard<= 06_51_j
HitachiCosminexus Developer Light Version 6<= 06_51_j
HitachiCosminexus Developer Professional Version 6<= 06_51_j
HitachiCosminexus Developer Standard Version 6<= 06_51_j
HitachiCosminexus Server<= 04_01
HitachiUcosminexus Application Server Enterprise<= 07_50_01
HitachiUcosminexus Application Server Standard<= 07_50_01
HitachiUcosminexus Developer Light<= 06_71_d
HitachiUcosminexus Developer Professional<= 07_50_01
HitachiUcosminexus Developer Standard<= 07_50_01
HitachiUcosminexus Service Architect<= 07_50_01
HitachiUcosminexus Service Platform<= 07_50_01
HitachiWeb Server01_00

Related Weaknesses (CWE)

References

FAQ

What is CVE-2007-5809?

CVE-2007-5809 is a vulnerability with a CVSS score of 4.3 (MEDIUM). Cross-site scripting (XSS) vulnerability in Hitachi Web Server 01-00 through 03-10, as used by certain Cosminexus products, allows remote attackers to inject arbitrary web script or HTML via unspecifi...

How severe is CVE-2007-5809?

CVE-2007-5809 has been rated MEDIUM with a CVSS base score of 4.3/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2007-5809?

Check the references section above for vendor advisories and patch information. Affected products include: Hitachi Cosminexus Application Server Enterprise, Hitachi Cosminexus Application Server Standard, Hitachi Cosminexus Developer Light Version 6, Hitachi Cosminexus Developer Professional Version 6, Hitachi Cosminexus Developer Standard Version 6.