PT-2008-2640 · Fujitsu · Fujitsu Interstage Application Server+2

Published

2008-02-27

·

Updated

2011-03-08

·

CVE-2008-1040

CVSS v2.0

10

High

VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Fujitsu Interstage Application Server versions 8.0.0 through 8.0.3 Fujitsu Interstage Application Server version 9.0.0 Fujitsu Interstage Studio versions 8.0.1 and 9.0.0 Fujitsu Interstage Apworks version 8.0.0
Description The issue is related to a buffer overflow in the Single Sign-On function, allowing remote attackers to execute arbitrary code via a long URI.
Recommendations For Fujitsu Interstage Application Server versions 8.0.0 through 8.0.3, consider restricting access to the Single Sign-On function until a patch is available. For Fujitsu Interstage Application Server version 9.0.0, consider restricting access to the Single Sign-On function until a patch is available. For Fujitsu Interstage Studio versions 8.0.1 and 9.0.0, consider restricting access to the Single Sign-On function until a patch is available. For Fujitsu Interstage Apworks version 8.0.0, consider restricting access to the Single Sign-On function until a patch is available. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Buffer Overflow

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2008-1040

Affected Products

Fujitsu Interstage Application Server
Fujitsu Interstage Apworks
Fujitsu Interstage Studio