Cosminexus Manager in Cosminexus Application Server 06-50 and later might assign the wrong user's group permissions to logical J2EE server processes, which allows local users to gain privileges.
Weaknesses in this category are related to the management of permissions, privileges, and other security features that are used to perform access control.
Link | Tags |
---|---|
http://osvdb.org/37854 | vdb entry |
http://www.hitachi-support.com/security_e/vuls_e/HS07-025_e/index-e.html | patch |
http://www.securityfocus.com/bid/25434 | patch vdb entry |
http://secunia.com/advisories/26589 | patch vendor advisory third party advisory |
https://exchange.xforce.ibmcloud.com/vulnerabilities/36245 | vdb entry |