CVE-2007-4124 - CVE House
Back to Database
Status published Medium CVE-2007-4124

The session failover function in Cosminexus Component Container in Cosminexus...

Vulnerability Description

The session failover function in Cosminexus Component Container in Cosminexus 6, 6.7, and 7 before 20070731, as used in multiple Hitachi products, can use session data for the wrong user under unspecified conditions, which might allow remote authenticated users to obtain sensitive information, corrupt another user's session data, and possibly gain privileges.

Impact Analysis

Refer to official advisory for detailed impact metrics.

Remediation

Ensure systems are updated to the latest vendor-supplied patch levels.

THREAT MONITOR

Am I Vulnerable?

Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2007-4124

Credits & Attribution

No credits recorded in the NVD database.

Affected Vendor

Affected Software

cosminexus application server, cosminexus collaboration portal, cosminexus developer, cosminexus erp integrator, cosminexus opentp1 web front-end set, electronic form workflow, groupmax collaboration portal, ucosminexus application server, ucosminexus collaboration portal, ucosminexus developer, ucosminexus erp integrator, ucosminexus opentp1 web front-end set, ucosminexus service architect, ucosminexus service platform
Vulnerable Versions:
6

Timeline

Official Publish: August 1st, 2007
Last Modified: August 7th, 2024
Added to House: July 18th, 2026

CVSS Vectors

Weaknesses (CWE)

No CWE data available

MITRE ATT&CK TTPs

No associated TTPs found for this vulnerability.