Lucene search

K
cve[email protected]CVE-2007-5810
HistoryNov 05, 2007 - 5:46 p.m.

CVE-2007-5810

2007-11-0517:46:00
CWE-20
web.nvd.nist.gov
24
hitachi web server
ssl validation
authentication spoofing
cve-2007-5810
nvd

5 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:L/Au:N/C:N/I:P/A:N

6.8 Medium

AI Score

Confidence

Low

0.005 Low

EPSS

Percentile

77.3%

Hitachi Web Server 01-00 through 03-00-01, as used by certain Cosminexus products, does not properly validate SSL client certificates, which might allow remote attackers to spoof authentication via a client certificate with a forged signature.

Affected configurations

NVD
Node
hitachicosminexus_application_server_enterpriseRange06_51_j
OR
hitachicosminexus_application_server_standardRange06_51_j
OR
hitachicosminexus_developer_light_version_6Range06_51_j
OR
hitachicosminexus_developer_professional_version_6Range06_51_j
OR
hitachicosminexus_developer_standard_version_6Range06_51_j
OR
hitachicosminexus_serverRange04_01
OR
hitachiucosminexus_application_server_enterpriseRange07_50_01
OR
hitachiucosminexus_application_server_standardRange07_50_01
OR
hitachiucosminexus_developer_lightRange06_71_d
OR
hitachiucosminexus_developer_professionalRange07_50_01
OR
hitachiucosminexus_developer_standardRange07_50_01
OR
hitachiucosminexus_service_architectRange07_50_01
OR
hitachiucosminexus_service_platformRange07_50_01
OR
hitachiweb_serverMatch01_00hpux
OR
hitachiweb_serverMatch01_00solaris
OR
hitachiweb_serverMatch01_01aix
OR
hitachiweb_serverMatch01_01linux
OR
hitachiweb_serverMatch01_01turbolinux
OR
hitachiweb_serverMatch01_01_dlinux
OR
hitachiweb_serverMatch01_02_dhpux
OR
hitachiweb_serverMatch01_02_dsolaris
OR
hitachiweb_serverMatch01_02_eaix
OR
hitachiweb_serverMatch02_00aix
OR
hitachiweb_serverMatch02_00hpux
OR
hitachiweb_serverMatch02_00linux
OR
hitachiweb_serverMatch02_00solaris
OR
hitachiweb_serverMatch02_00turbolinux
OR
hitachiweb_serverMatch02_00windows
OR
hitachiweb_serverMatch02_00_alinux
OR
hitachiweb_serverMatch02_02hpux
OR
hitachiweb_serverMatch02_02hpux\(ipf\)
OR
hitachiweb_serverMatch02_02linux
OR
hitachiweb_serverMatch02_04_baix
OR
hitachiweb_serverMatch02_04_bhpux
OR
hitachiweb_serverMatch02_04_bhpux\(ipf\)
OR
hitachiweb_serverMatch02_04_bsolaris
OR
hitachiweb_serverMatch02_04_bwindows
OR
hitachiweb_serverMatch02_06_alinux
OR
hitachiweb_serverMatch03_00aix
OR
hitachiweb_serverMatch03_00hpux\(ipf\)
OR
hitachiweb_serverMatch03_00linux
OR
hitachiweb_serverMatch03_00windows
OR
hitachiweb_serverMatch03_00_01solaris
OR
hitachiweb_serverMatch03_00_01windows

5 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:L/Au:N/C:N/I:P/A:N

6.8 Medium

AI Score

Confidence

Low

0.005 Low

EPSS

Percentile

77.3%

Related for CVE-2007-5810