Cosminexus Application Server

Vendor:

First CVE: Oct 6, 2005 · Active for 20 years

6
Total CVEs
More Total CVEs than 80% of tracked products
2.0
Avg CVEs / Year
Higher CVE frequency than 60% of tracked products
6.9
Avg CVSS
Higher Avg CVSS than 39% of tracked products
0.0%
KEV Rate
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact Cosminexus Application Server over time

Volume of CVEsAvg CVSS Base Score
First CVE
Oct 6, 2005
20 years ago
Most Recent CVE
Apr 21, 2010
5,939 days ago

CVE Severity & Scoring

Cosminexus Application Server6 CVEs
All CVEs352,427 CVEs
LowMediumHigh
Attack Vector
Local0 (0.0%)
Network0 (0.0%)
Unknown6 (100.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low0 (0.0%)
High0 (0.0%)
Unknown6 (100.0%)
User Interaction
None0 (0.0%)
Unknown6 (100.0%)
Required0 (0.0%)
Privileges Required
Low0 (0.0%)
High0 (0.0%)
None0 (0.0%)
Unknown6 (100.0%)

Top CVEs

Signals from CVEs in this product scope (6 CVEs).

6 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
Buffer overflow in Hitachi Cosminexus V4 through V8, Processing Kit for XML, and Developer's Kit for Java, as used in products such as uCosminexus, Electronic Form Workflow, Groupm
Apr 21, 20109.326NONO
Buffer overflow in Hitachi Cosminexus V4 through V7, Processing Kit for XML before 20070511, Developer's Kit for Java before 20070312, and third-party products that use this softwa
Jul 15, 200710.025NONO
Unspecified vulnerability in the ADM daemon in Hitachi TPBroker before 20070706 allows remote attackers to cause a denial of service (daemon crash) via a certain request.
Jul 9, 20077.820NONO
Multiple cross-site scripting (XSS) vulnerabilities in multiple Hitachi Web Server, uCosminexus, and Cosminexus products before 20070124 allow remote attackers to inject arbitrary
Jan 26, 20076.818NONO
The AJP connector in Apache Tomcat 4.0.1 through 4.0.6 and 4.1.0 through 4.1.36, as used in Hitachi Cosminexus Application Server and standalone, does not properly handle when a co
Oct 6, 20052.616NONO
The session failover function in Cosminexus Component Container in Cosminexus 6, 6.7, and 7 before 20070731, as used in multiple Hitachi products, can use session data for the wron
Aug 1, 20074.915NONO

Exploit Exposure

Signals from CVEs in this product scope (6 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

Signals from CVEs in this product scope (6 CVEs).

Media Mentions

Signals from CVEs in this product scope (6 CVEs).

Top CNAs Publishing CVEs For Cosminexus Application Server

Top CWEs

Versions

VersionCVE CountAvg CVSSAvg EPSSKEVExploits
637.01.9%00
519.33.1%00
06-51-\/k19.33.1%00
06-51-\/e19.33.1%00
06-51-\/b19.33.1%00
06_51_06_51_g110.02.2%00
06_51_06_51_c110.02.2%00
06_51_06_51_b110.02.2%00
06-5119.33.1%00
06-50-\/i19.33.1%00
06-50-\/f19.33.1%00
06-50-\/e19.33.1%00
06-50-\/c19.33.1%00
06-50-\/b19.33.1%00
06_50_06_50_f110.02.2%00
06_50_06_50_e110.02.2%00
06_50_06_50_d110.02.2%00
06_50_06_50_c110.02.2%00
06_50_06_50_b110.02.2%00
06-5019.33.1%00