Cybertrion Systems

[3/5] Hitachi Cosminexus JSSE SSL/TLS Handshake Denial of Service

October 5th, 2007 by
[3/5] Hitachi Cosminexus JSSE SSL/TLS Handshake Denial of Service

:A vulnerability has been reported in Hitachi Cosminexus, which can be exploited by malicious people to cause a DoS (Denial of Service).The vulnerability is caused due to an error in the JSSE (Java Secure Socket Extension) of Cosminexus Developer’s Kit for Java(TM) when handling invalid SSL/TLS handshake requests. This can be exploited to cause a DoS on an affected system that uses JSEE APIs to handle SSL/TLS connections.This may be related to vulnerability #1 in:SA26015The vulnerability affects Cosminexus version 7.5 (see vendor’s advisory for details).Solution:Please see the vendor’s advisory for fix details.Provided and/or discovered by:Reported by the vendor.Original Advisory:http://www.hitachi-support.com/security_e/vuls_e/HS07-031_e/index-e.htmlOther References:SA26015:http://secunia.com/advisories/26015/

Original post by Pankaj

[3/5] Hitachi Cosminexus JSSE SSL/TLS Handshake Denial of Service

Related Articles:
  • [2/5] Hitachi Cosminexus Agent Unspecified Denial of Service Vulnerability
  • [4/5] Hitachi Cosminexus Products DoS and Buffer Overflow Vulnerabilities
  • [2/5] Hitachi Cosminexus Products JavaDoc Cross-Site Scripting
  • [1/5] Hitachi Cosminexus Application Server Incorrect Handling of Group Permissions
  • [3/5] Java Secure Socket Extension Denial of Service Vulnerability


  • Posted in Advisories - Exploits | | [3/5] Hitachi Cosminexus JSSE SSL/TLS Handshake Denial of Service

    << [4/5] Fedora update for openoffice.org | [3/5] Borland InterBase Multiple Buffer Overflow Vulnerabilities >>