Cybertrion Systems

[2/5] Hitachi Web Server Multiple Vulnerabilities

October 31st, 2007 by
[2/5] Hitachi Web Server Multiple Vulnerabilities

:Some vulnerabilities have been reported in the Hitachi Web Server, which can be exploited by malicious people to bypass certain security restrictions or conduct cross-site scripting attacks.1) An error exists within the handling of SSL requests. This can be exploited to trick a vulnerable server into accepting a forged signature.2) An error exists in the Hitachi Web Server when generating server-status pages for potentially malicious scripts . This can be exploited to execute arbitrary HTML and script code in a user’s browser session in context of an affected site.See the vendor advisories for a list of affected versions.Solution:Updates are available for some versions. See the vendor’s advisories for details or contact a Hitachi support service representative.Provided and/or discovered by:Reported by the vendor.Original Advisory:http://www.hitachi-support.com/security_e/vuls_e/HS07-034_e/index-e.htmlhttp://www.hitachi-support.com/security_e/vuls_e/HS07-035_e/index-e.html

Original post by Pankaj

[2/5] Hitachi Web Server Multiple Vulnerabilities

Related Articles:
  • [3/5] Hitachi TP1/Server Base Unspecified Denial of Service
  • [1/5] Hitachi Cosminexus Application Server Incorrect Handling of Group Permissions
  • [2/5] Hitachi Web Server Cross-Site Scripting Vulnerabilities
  • [4/5] Hitachi Cosminexus Products DoS and Buffer Overflow Vulnerabilities
  • [2/5] Hitachi JP1/HiCommand Series Two Vulnerabilities


  • Posted in Advisories - Exploits | | [2/5] Hitachi Web Server Multiple Vulnerabilities

    << [2/5] Hitachi Products Information Disclosure Vulnerability | [2/5] RSA Registration Manager Cross-Site Scripting Vulnerabilities >>