Hitachi Cosminexus jaxp xml Processing Arbitrary Code Execution Vulnerability
Release date:
Updated on:
Affected Systems:
Hitachi Cosminexus 9.x
Hitachi Cosminexus 8.x
Hitachi Cosminexus 7.x
Description:
--------------------------------------------------------------------------------
Bugtraq id: 65208
CVE (CAN) ID: CVE-2013-5986
Hitachi Cosminexus is a high-performance electronic business platform.
When multiple Hitachi Cosminexus products process XML, an error occurs in javastc, which can lead to arbitrary code execution.
<* Source: Marcin Koscielnicki
Link: http://secunia.com/advisories/56832/
*>
Suggestion:
--------------------------------------------------------------------------------
Vendor patch:
Hitachi
-------
The vendor has released a patch to fix this security problem. Please download it from the vendor's homepage:
Http://www.hitachi.co.jp/Prod/comp/soft1/security/
Http://www.hitachi.co.jp/Prod/comp/soft1/global/security/info/vuls/HS14-005/index.html