2011-03-09

日立 Cosminexus, 日立 Developer's Kit, 日立 uCosminexus Application, Novell openSUSE

ソフト名:日立 Cosminexus 5.x/6.x/7.x/8.x/Application Server 6.x/Server 4.x/Studio 4.x, 日立 Developer's Kit for Java, 日立 uCosminexus Application Server/Client/Developer/Operator/Portal Framework/Service Architect/Service Platform, Novell openSUSE 11.2/11.3
回避策:HS11-003にて対応, openSUSE-SU-2011:0155-1にて対応
脆弱性:データ操作, 機密情報の奪取, DoS攻撃, システムアクセス, 無限ループ, 入力検証エラー, リモートコード実行, ヒープメモリ破壊
ソース:
http://www.hitachi.co.jp/Prod/comp/soft1/global/prod/products.html#Cosminexus
http://www.opensuse.org/en/
http://www.hitachi.co.jp/Prod/comp/soft1/global/security/info/vuls/HS11-003/index.html
http://www.hitachi.co.jp/Prod/comp/soft1/security/info/./vuls/HS11-003/index.html
https://hermes.opensuse.org/messages/7533009
http://secunia.com/advisories/43262/
http://secunia.com/advisories/43624/
http://secunia.com/advisories/43627/
http://dvw-j.blogspot.com/2011/02/sun-java-ibm-java-ibm-websphere.html
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-4448
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-4450
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-4454
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-4462
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-4465
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-4468
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-4469
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-4470
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-4471
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-4472
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-4473
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-4476
CVE:CVE-2010-4448, CVE-2010-4450, CVE-2010-4454, CVE-2010-4462, CVE-2010-4465, CVE-2010-4468, CVE-2010-4469, CVE-2010-4470, CVE-2010-4471, CVE-2010-4472, CVE-2010-4473, CVE-2010-4476
危険性:High Risk

0 件のコメント:

コメントを投稿