Search

published date: December 31, 2004

CVE-2004-1478 : JRun 4.0 does not...

Description

JRun 4.0 does not properly generate and handle the JSESSIONID, which allows remote attackers to perform a session fixation attack and hijack a user's HTTP session.

Product(s):

  • Hitachi Cosminexus Enterprise 01_01_1 Enterprise Edition
  • Hitachi Cosminexus Enterprise 01_01_1 Standard Edition
  • Hitachi Cosminexus Enterprise 01_02_2 Enterprise Edition
  • Hitachi Cosminexus Enterprise 01_02_2 Standard Edition
  • Hitachi Cosminexus Server Web 01-01 1
  • Hitachi Cosminexus Server Web 01-01 2

Question to Ask Vendors:

  1. Can you confirm whether your systems are affected by CVE-2004-1478, and if so, what steps are you currently taking to mitigate this vulnerability?
  2. What is your estimated timeline for fully resolving CVE-2004-1478 in your products or services, and how will you communicate updates on this issue to us as your customer?

READY TO GET RESULTS YOU CAN TRUST?