Cosminexus Portal Framework Information Disclosure Vulnerability
BID:11128
Info
Cosminexus Portal Framework Information Disclosure Vulnerability
| Bugtraq ID: | 11128 |
| Class: | Design Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Sep 07 2004 12:00AM |
| Updated: | Sep 07 2004 12:00AM |
| Credit: | This vulnerability was reported by the vendor. |
| Vulnerable: |
Hitachi Cosminexus Portal Framework 06-10-/C (Windows) Hitachi Cosminexus Portal Framework 02-03-/C Hitachi Cosminexus Portal Framework 02-03 Hitachi Cosminexus Portal Framework 02-02-/B Hitachi Cosminexus Portal Framework 02-02-/A Hitachi Cosminexus Portal Framework 02-02 Hitachi Cosminexus Portal Framework 02-01 Hitachi Cosminexus Portal Framework 02-00-/A Hitachi Cosminexus Portal Framework 02-00 Hitachi Cosminexus Portal Framework 01-02-/A Hitachi Cosminexus Portal Framework 01-02 Hitachi Cosminexus Portal Framework 01-01 Hitachi Cosminexus Portal Framework 01-00-/A |
| Not Vulnerable: |
Hitachi Cosminexus Portal Framework 02-03-/D Hitachi Cosminexus Portal Framework 02-02-/C Hitachi Cosminexus Portal Framework 02-02-/A Hitachi Cosminexus Portal Framework 02-00-/A Hitachi Cosminexus Portal Framework 01-02-/B Hitachi Cosminexus Portal Framework 01-02-/A Hitachi Cosminexus Portal Framework 01-00-/A |
Discussion
Cosminexus Portal Framework Information Disclosure Vulnerability
Cosminexus Portal Framework is reported susceptible to an information disclosure vulnerability.
In certain undisclosed circumstances, it may be possible for contents of cache objects to be replaced by the contents of other cache objects. This may allow for potentially sensitive information to be sent to a different user than intended. This may include potentially sensitive information, that may aid malicious users in attacks against the application.
As this application framework is designed to handle business information, attackers may be able to gain access to potentially sensitive business data.
Cosminexus Portal Framework is reported susceptible to an information disclosure vulnerability.
In certain undisclosed circumstances, it may be possible for contents of cache objects to be replaced by the contents of other cache objects. This may allow for potentially sensitive information to be sent to a different user than intended. This may include potentially sensitive information, that may aid malicious users in attacks against the application.
As this application framework is designed to handle business information, attackers may be able to gain access to potentially sensitive business data.
Exploit / POC
Cosminexus Portal Framework Information Disclosure Vulnerability
Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution / Fix
Cosminexus Portal Framework Information Disclosure Vulnerability
Solution:
The vendor has released an alert along with fixes to resolve this issue. Please see the referenced alert for further information. Contact the vendor for information on obtaining fixes.
Solution:
The vendor has released an alert along with fixes to resolve this issue. Please see the referenced alert for further information. Contact the vendor for information on obtaining fixes.
References
Cosminexus Portal Framework Information Disclosure Vulnerability
References:
References: