PT-2008-2640 · Fujitsu · Fujitsu Interstage Application Server+2
Published
2008-02-27
·
Updated
2011-03-08
·
CVE-2008-1040
CVSS v2.0
10
High
| Vector | AV:N/AC:L/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
Fujitsu Interstage Application Server versions 8.0.0 through 8.0.3
Fujitsu Interstage Application Server version 9.0.0
Fujitsu Interstage Studio versions 8.0.1 and 9.0.0
Fujitsu Interstage Apworks version 8.0.0
Description
The issue is related to a buffer overflow in the Single Sign-On function, allowing remote attackers to execute arbitrary code via a long URI.
Recommendations
For Fujitsu Interstage Application Server versions 8.0.0 through 8.0.3, consider restricting access to the Single Sign-On function until a patch is available.
For Fujitsu Interstage Application Server version 9.0.0, consider restricting access to the Single Sign-On function until a patch is available.
For Fujitsu Interstage Studio versions 8.0.1 and 9.0.0, consider restricting access to the Single Sign-On function until a patch is available.
For Fujitsu Interstage Apworks version 8.0.0, consider restricting access to the Single Sign-On function until a patch is available.
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Buffer Overflow
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Fujitsu Interstage Application Server
Fujitsu Interstage Apworks
Fujitsu Interstage Studio