CVE-2010-1942
Summary
| CVE | CVE-2010-1942 |
|---|---|
| State | PUBLISHED |
| Assigner | mitre |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2010-05-19 12:08:04 UTC |
| Updated | 2026-04-29 01:13:23 UTC |
| Description | Unspecified vulnerability in the Servlet service in Fujitsu Limited Interstage Application Server 3.0 through 7.0, as used in Interstage Application Framework Suite, Interstage Business Application Server, and Interstage List Manager, allows attackers to obtain sensitive information or force invalid requests to be processed via unknown vectors related to unspecified invalid requests and settings on the load balancing device. |
Risk And Classification
Primary CVSS: v2.0 6.4 from [email protected]
AV:N/AC:L/Au:N/C:P/I:P/A:N
Problem Types: NVD-CWE-noinfo | n/a
CVSS v2.0 Breakdown
Access Vector
NetworkAccess Complexity
LowAuthentication
NoneConfidentiality
PartialIntegrity
PartialAvailability
NoneAV:N/AC:L/Au:N/C:P/I:P/A:N
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Fujitsu | Interstage Application Server | 3.0 | All | enterprise | All |
| Application | Fujitsu | Interstage Application Server | 3.0 | All | standard | All |
| Application | Fujitsu | Interstage Application Server | 4.0 | All | enterprise | All |
| Application | Fujitsu | Interstage Application Server | 4.0 | All | standard | All |
| Application | Fujitsu | Interstage Application Server | 4.0 | All | web_j | All |
| Application | Fujitsu | Interstage Application Server | 4.1 | All | standard | All |
| Application | Fujitsu | Interstage Application Server | 4.1 | All | web_j | All |
| Application | Fujitsu | Interstage Application Server | 5.0 | All | enterprise | All |
| Application | Fujitsu | Interstage Application Server | 5.0 | All | standard | All |
| Application | Fujitsu | Interstage Application Server | 5.0 | All | web_j | All |
| Application | Fujitsu | Interstage Application Server | 5.0.1 | All | enterprise | All |
| Application | Fujitsu | Interstage Application Server | 5.0.1 | All | plus_developer | All |
| Application | Fujitsu | Interstage Application Server | 6.0 | All | enterprise | All |
| Application | Fujitsu | Interstage Application Server | 6.0 | All | plus | All |
| Application | Fujitsu | Interstage Application Server | 7.0 | All | enterprise | All |
| Application | Fujitsu | Interstage Application Server | 7.0 | All | plus | All |
| Application | Fujitsu | Interstage Application Server | 7.0 | All | standard | All |
| Application | Fujitsu | Interstage Application Server | 7.0.1 | All | enterprise | All |
| Application | Fujitsu | Interstage Application Server | 7.0.1 | All | plus | All |
Vendor Declared Affected Products
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Fujitsu Interstage Application Server Servlet Component Vulnerability - Advisories - Community | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | Vendor Advisory |
| This page provides Security Information. - Fujitsu Global | af854a3a-2127-422b-91ae-364da2661108 | www.fujitsu.com | Patch, Vendor Advisory |
| IBM X-Force Exchange | af854a3a-2127-422b-91ae-364da2661108 | exchange.xforce.ibmcloud.com | |
| jvndb.jvn.jp/ja/contents/2010/JVNDB-2010-000018.html | af854a3a-2127-422b-91ae-364da2661108 | jvndb.jvn.jp | |
| JVN#90248889 Interstage Application Server vulnerable in request processing | af854a3a-2127-422b-91ae-364da2661108 | jvn.jp | |
| Webmail : Solution de messagerie professionnelle - OVHcloud- OVH | af854a3a-2127-422b-91ae-364da2661108 | www.vupen.com | Patch, Vendor Advisory |
| ソフトウェア セキュリティ - Fujitsu Japan | af854a3a-2127-422b-91ae-364da2661108 | software.fujitsu.com | Vendor Advisory |
| osvdb.org/64703 | af854a3a-2127-422b-91ae-364da2661108 | osvdb.org | |
| Fujitsu Interstage Application Server Servlet Component Security Vulnerability | af854a3a-2127-422b-91ae-364da2661108 | www.securityfocus.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.