PT-2008-2640 · Fujitsu · Fujitsu Interstage Application Server+2
Publicado
2008-02-27
·
Atualizado
2011-03-08
·
CVE-2008-1040
CVSS v2.0
10
Alta
| Vetor | AV:N/AC:L/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
Fujitsu Interstage Application Server versions 8.0.0 through 8.0.3
Fujitsu Interstage Application Server version 9.0.0
Fujitsu Interstage Studio versions 8.0.1 and 9.0.0
Fujitsu Interstage Apworks version 8.0.0
Description
The issue is related to a buffer overflow in the Single Sign-On function, allowing remote attackers to execute arbitrary code via a long URI.
Recommendations
For Fujitsu Interstage Application Server versions 8.0.0 through 8.0.3, consider restricting access to the Single Sign-On function until a patch is available.
For Fujitsu Interstage Application Server version 9.0.0, consider restricting access to the Single Sign-On function until a patch is available.
For Fujitsu Interstage Studio versions 8.0.1 and 9.0.0, consider restricting access to the Single Sign-On function until a patch is available.
For Fujitsu Interstage Apworks version 8.0.0, consider restricting access to the Single Sign-On function until a patch is available.
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Buffer Overflow
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Fujitsu Interstage Application Server
Fujitsu Interstage Apworks
Fujitsu Interstage Studio