HIGH · 9.3

CVE-2009-4776

Buffer overflow in Hitachi Cosminexus V4 through V8, Processing Kit for XML, and Developer's Kit for Java, as used in products such as uCosminexus, Electronic Form Workflow, Groupmax, and IBM XL C/C++...

Vulnerability Description

Buffer overflow in Hitachi Cosminexus V4 through V8, Processing Kit for XML, and Developer's Kit for Java, as used in products such as uCosminexus, Electronic Form Workflow, Groupmax, and IBM XL C/C++ Enterprise Edition 7 and 8, allows remote attackers to have an unknown impact via vectors related to the use of GIF image processing APIs by a Java application, and a different issue from CVE-2007-3794.

CVSS Score

9.3

HIGH

AV:N/AC:M/Au:N/C:C/I:C/A:C
Confidentiality
COMPLETE
Integrity
COMPLETE
Availability
COMPLETE

Affected Products

VendorProductVersions
HitachiUcosminexus\/Opentp1 Web Web Front-Endset02-70
HitachiUcosminexus Application Server06-70
HitachiUcosminexus Client06-70
HitachiUcosminexus Collaboration06-20
HitachiUcosminexus Developer6
HitachiUcosminexus Operator6.7
HitachiUcosminexus Service Architect6.7
HitachiUcosminexus Service Platform6.7
HitachiProcessing Kit For Xml01-00
HitachiIbm Xl C\/C\+\+ V7 For Aix \& Hitachi Developer\'S Kit For Java01-00
HitachiIbm Xl C\/C\+\+ V8 For Aix \& Hitachi Developer\'S Kit For Java01-00
HitachiGroupmax Collaboration07-20
HitachiElectronic Form Workflow Set07-50
HitachiElectronic Form Workflow-Standard Set06-70
HitachiElectronic Form Workflow-Professional Set07-50
HitachiElectronic Form Workflow-Professional Library Set06-70
HitachiElectronic Form Workflow-Developer Set07-50
HitachiElectronic Form Workflow-Developer Client Set06-70
HitachiDeveloper\'S Kit For JavaAll versions
HitachiCosminexus\/Opentp1 Web Web Front-Endset01-00

Related Weaknesses (CWE)

References

FAQ

What is CVE-2009-4776?

CVE-2009-4776 is a vulnerability with a CVSS score of 9.3 (HIGH). Buffer overflow in Hitachi Cosminexus V4 through V8, Processing Kit for XML, and Developer's Kit for Java, as used in products such as uCosminexus, Electronic Form Workflow, Groupmax, and IBM XL C/C++...

How severe is CVE-2009-4776?

CVE-2009-4776 has been rated HIGH with a CVSS base score of 9.3/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2009-4776?

Check the references section above for vendor advisories and patch information. Affected products include: Hitachi Ucosminexus\/Opentp1 Web Web Front-Endset, Hitachi Ucosminexus Application Server, Hitachi Ucosminexus Client, Hitachi Ucosminexus Collaboration, Hitachi Ucosminexus Developer.