Hitachi Cosminexus Products Oracle Java Multiple Vulnerabilities
RISK: High Risk
TYPE: Servers - Other Servers
Multiple vulnerabilities have been identified in various Hitachi Cosminexus products, which can be exploited by malicious, local users to gain escalated privileges and by malicious people to disclose certain sensitive information, manipulate certain data, cause a DoS (Denial of Service), and compromise a vulnerable system.
The vulnerabilities exist in the bundled version of Cosminexus Developer's Kit for Java. For detail of the vulnerability, please refer to SA13041701.
Impact
- Denial of Service
- Remote Code Execution
- Information Disclosure
System / Technologies affected
- Cosminexus 7.x
- Cosminexus 8.x
- Cosminexus 9.x
- Cosminexus Application Server 5.x
- Cosminexus Application Server 6.x
- Cosminexus Client 6.x
- Cosminexus Developer 5.x
- Cosminexus Developer 6.x
- Cosminexus Server 4.x
- Cosminexus Studio 4.x
- Cosminexus Studio 5.x
- uCosminexus Application Server
- uCosminexus Client
- uCosminexus Developer
- uCosminexus Operator
- uCosminexus Service Architect
- uCosminexus Service Platform
Solutions
Before installation of the software, please visit the software manufacturer web-site for more details.
Vulnerability Identifier
- CVE-2013-0401
- CVE-2013-1491
- CVE-2013-1518
- CVE-2013-1537
- CVE-2013-1540
- CVE-2013-1557
- CVE-2013-1558
- CVE-2013-1563
- CVE-2013-1569
- CVE-2013-2383
- CVE-2013-2384
- CVE-2013-2394
- CVE-2013-2417
- CVE-2013-2418
- CVE-2013-2419
- CVE-2013-2420
- CVE-2013-2422
- CVE-2013-2424
- CVE-2013-2429
- CVE-2013-2430
- CVE-2013-2432
- CVE-2013-2433
- CVE-2013-2435
- CVE-2013-2440
Source
Related Link
Share with