PT-2008-2640 · Fujitsu · Fujitsu Interstage Application Server+2

Publicado

2008-02-27

·

Atualizado

2011-03-08

·

CVE-2008-1040

CVSS v2.0

10

Alta

VetorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Fujitsu Interstage Application Server versions 8.0.0 through 8.0.3 Fujitsu Interstage Application Server version 9.0.0 Fujitsu Interstage Studio versions 8.0.1 and 9.0.0 Fujitsu Interstage Apworks version 8.0.0
Description The issue is related to a buffer overflow in the Single Sign-On function, allowing remote attackers to execute arbitrary code via a long URI.
Recommendations For Fujitsu Interstage Application Server versions 8.0.0 through 8.0.3, consider restricting access to the Single Sign-On function until a patch is available. For Fujitsu Interstage Application Server version 9.0.0, consider restricting access to the Single Sign-On function until a patch is available. For Fujitsu Interstage Studio versions 8.0.1 and 9.0.0, consider restricting access to the Single Sign-On function until a patch is available. For Fujitsu Interstage Apworks version 8.0.0, consider restricting access to the Single Sign-On function until a patch is available. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Buffer Overflow

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2008-1040

Produtos afetados

Fujitsu Interstage Application Server
Fujitsu Interstage Apworks
Fujitsu Interstage Studio