Cosminexus Application Server
Vendor:
First CVE: Oct 6, 2005 · Active for 20 years
6
Total CVEs
More Total CVEs than 80% of tracked products
2.0
Avg CVEs / Year
Higher CVE frequency than 60% of tracked products
6.9
Avg CVSS
Higher Avg CVSS than 39% of tracked products
0.0%
KEV Rate
Bottom 1%
Trends Over Time
The number and severity of CVEs published that impact Cosminexus Application Server over time
Volume of CVEsAvg CVSS Base Score
First CVE
Oct 6, 2005
20 years ago
Most Recent CVE
Apr 21, 2010
5,939 days ago
CVE Severity & Scoring
Cosminexus Application Server6 CVEs
17%
33%
50%
All CVEs352,427 CVEs
45%
40%
11%
LowMediumHigh
Attack Vector
Local0 (0.0%)
Network0 (0.0%)
Unknown6 (100.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low0 (0.0%)
High0 (0.0%)
Unknown6 (100.0%)
User Interaction
None0 (0.0%)
Unknown6 (100.0%)
Required0 (0.0%)
Privileges Required
Low0 (0.0%)
High0 (0.0%)
None0 (0.0%)
Unknown6 (100.0%)
Top CVEs
Signals from CVEs in this product scope (6 CVEs).
6 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2009-4776HIGH Buffer overflow in Hitachi Cosminexus V4 through V8, Processing Kit for XML, and Developer's Kit for Java, as used in products such as uCosminexus, Electronic Form Workflow, Groupm | Apr 21, 2010 | 9.3 | 26 | NO | NO |
CVE-2007-3794HIGH Buffer overflow in Hitachi Cosminexus V4 through V7, Processing Kit for XML before 20070511, Developer's Kit for Java before 20070312, and third-party products that use this softwa | Jul 15, 2007 | 10.0 | 25 | NO | NO |
CVE-2007-3626HIGH Unspecified vulnerability in the ADM daemon in Hitachi TPBroker before 20070706 allows remote attackers to cause a denial of service (daemon crash) via a certain request. | Jul 9, 2007 | 7.8 | 20 | NO | NO |
CVE-2007-0514MEDIUM Multiple cross-site scripting (XSS) vulnerabilities in multiple Hitachi Web Server, uCosminexus, and Cosminexus products before 20070124 allow remote attackers to inject arbitrary | Jan 26, 2007 | 6.8 | 18 | NO | NO |
The AJP connector in Apache Tomcat 4.0.1 through 4.0.6 and 4.1.0 through 4.1.36, as used in Hitachi Cosminexus Application Server and standalone, does not properly handle when a co | Oct 6, 2005 | 2.6 | 16 | NO | NO |
CVE-2007-4124MEDIUM The session failover function in Cosminexus Component Container in Cosminexus 6, 6.7, and 7 before 20070731, as used in multiple Hitachi products, can use session data for the wron | Aug 1, 2007 | 4.9 | 15 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (6 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%
Social Chatter
Signals from CVEs in this product scope (6 CVEs).
Media Mentions
Signals from CVEs in this product scope (6 CVEs).
Top CNAs Publishing CVEs For Cosminexus Application Server
Top CWEs
Versions
| Version | CVE Count | Avg CVSS | Avg EPSS | KEV | Exploits |
|---|---|---|---|---|---|
| 6 | 3 | 7.0 | 1.9% | 0 | 0 |
| 5 | 1 | 9.3 | 3.1% | 0 | 0 |
| 06-51-\/k | 1 | 9.3 | 3.1% | 0 | 0 |
| 06-51-\/e | 1 | 9.3 | 3.1% | 0 | 0 |
| 06-51-\/b | 1 | 9.3 | 3.1% | 0 | 0 |
| 06_51_06_51_g | 1 | 10.0 | 2.2% | 0 | 0 |
| 06_51_06_51_c | 1 | 10.0 | 2.2% | 0 | 0 |
| 06_51_06_51_b | 1 | 10.0 | 2.2% | 0 | 0 |
| 06-51 | 1 | 9.3 | 3.1% | 0 | 0 |
| 06-50-\/i | 1 | 9.3 | 3.1% | 0 | 0 |
| 06-50-\/f | 1 | 9.3 | 3.1% | 0 | 0 |
| 06-50-\/e | 1 | 9.3 | 3.1% | 0 | 0 |
| 06-50-\/c | 1 | 9.3 | 3.1% | 0 | 0 |
| 06-50-\/b | 1 | 9.3 | 3.1% | 0 | 0 |
| 06_50_06_50_f | 1 | 10.0 | 2.2% | 0 | 0 |
| 06_50_06_50_e | 1 | 10.0 | 2.2% | 0 | 0 |
| 06_50_06_50_d | 1 | 10.0 | 2.2% | 0 | 0 |
| 06_50_06_50_c | 1 | 10.0 | 2.2% | 0 | 0 |
| 06_50_06_50_b | 1 | 10.0 | 2.2% | 0 | 0 |
| 06-50 | 1 | 9.3 | 3.1% | 0 | 0 |