Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2007-4564


Cosminexus Manager in Cosminexus Application Server 07-00 and later might assign the wrong user's group permissions to logical user server processes, which allows local users to gain privileges.


Security Impact Summary

CVE-2007-4564 is a security vulnerability that . Impacting 7 products from hitachi, from hitachi, from hitachi and 4 others, organizations running these solutions should prioritize assessment and patching.

Historical Context

Originally identified in 2007, this vulnerability predates many modern security frameworks and practices. The vulnerability landscape of that era was characterized by different threat models and less mature defense mechanisms compared to contemporary standards.


Published

2007-08-28T01:17:00.000

Last Modified

2025-04-09T00:30:58.490

Status

Deferred

Source

[email protected]

Severity

CVSSv2: 4.6 (MEDIUM)

CVSSv2 Vector

AV:L/AC:L/Au:N/C:P/I:P/A:P

  • Access Vector: LOCAL
  • Access Complexity: LOW
  • Authentication: NONE
  • Confidentiality Impact: PARTIAL
  • Integrity Impact: PARTIAL
  • Availability Impact: PARTIAL
Exploitability Score

3.9

Impact Score

6.4

Weaknesses
  • Type: Primary
    CWE-264

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application hitachi cosminexus_application_server_enterprise 06_50 Yes
Application hitachi cosminexus_application_server_enterprise 06_50 Yes
Application hitachi cosminexus_application_server_enterprise 06_50 Yes
Application hitachi cosminexus_application_server_enterprise 06_50 Yes
Application hitachi cosminexus_application_server_enterprise 06_50 Yes
Application hitachi cosminexus_application_server_enterprise 06_50_b Yes
Application hitachi cosminexus_application_server_enterprise 06_50_c Yes
Application hitachi cosminexus_application_server_enterprise 06_50_c_1 Yes
Application hitachi cosminexus_application_server_enterprise 06_50_c_1 Yes
Application hitachi cosminexus_application_server_enterprise 06_50_e_1 Yes
Application hitachi cosminexus_application_server_enterprise 06_50_f Yes
Application hitachi cosminexus_application_server_enterprise 06_51 Yes
Application hitachi cosminexus_application_server_enterprise 06_51_b_1 Yes
Application hitachi cosminexus_application_server_enterprise 06_51_c Yes
Application hitachi cosminexus_application_server_standard 06_50 Yes
Application hitachi cosminexus_application_server_standard 06_50 Yes
Application hitachi cosminexus_application_server_standard 06_50 Yes
Application hitachi cosminexus_application_server_standard 06_50 Yes
Application hitachi cosminexus_application_server_standard 06_50 Yes
Application hitachi cosminexus_application_server_standard 06_50_b Yes
Application hitachi cosminexus_application_server_standard 06_50_c Yes
Application hitachi cosminexus_application_server_standard 06_50_c_1 Yes
Application hitachi cosminexus_application_server_standard 06_50_c_1 Yes
Application hitachi cosminexus_application_server_standard 06_50_e_1 Yes
Application hitachi cosminexus_application_server_standard 06_50_f Yes
Application hitachi cosminexus_application_server_standard 06_51 Yes
Application hitachi cosminexus_application_server_standard 06_51 Yes
Application hitachi cosminexus_application_server_standard 06_51_b_1 Yes
Application hitachi cosminexus_application_server_standard 06_51_c Yes
Application hitachi electronic_form_workflow_-_standard_set 07_00 Yes
Application hitachi electronic_form_workflow_-_standard_set 07_00_b Yes
Application hitachi electronic_form_workflow_-professional_library_set 07_00 Yes
Application hitachi electronic_form_workflow_-professional_library_set 07_00_b Yes
Application hitachi ucosminexus_application_server_enterprise 06_70 Yes
Application hitachi ucosminexus_application_server_enterprise 06_70 Yes
Application hitachi ucosminexus_application_server_enterprise 06_70_a Yes
Application hitachi ucosminexus_application_server_enterprise 06_70_a Yes
Application hitachi ucosminexus_application_server_enterprise 06_70_b Yes
Application hitachi ucosminexus_application_server_enterprise 06_70_b Yes
Application hitachi ucosminexus_application_server_enterprise 06_70_b Yes
Application hitachi ucosminexus_application_server_enterprise 06_70_b Yes
Application hitachi ucosminexus_application_server_enterprise 06_70_b_1 Yes
Application hitachi ucosminexus_application_server_enterprise 06_70_d Yes
Application hitachi ucosminexus_application_server_enterprise 06_70_g Yes
Application hitachi ucosminexus_application_server_enterprise 06_71 Yes
Application hitachi ucosminexus_application_server_enterprise 06_71_b Yes
Application hitachi ucosminexus_application_server_enterprise 06_71_b Yes
Application hitachi ucosminexus_application_server_enterprise 06_71_c Yes
Application hitachi ucosminexus_application_server_enterprise 06_72_1 Yes
Application hitachi ucosminexus_application_server_enterprise 06_72_b Yes
Application hitachi ucosminexus_application_server_enterprise 06_72_b Yes
Application hitachi ucosminexus_application_server_enterprise 06_72_g Yes
Application hitachi ucosminexus_application_server_enterprise 07-00-01 Yes
Application hitachi ucosminexus_application_server_enterprise 07_00 Yes
Application hitachi ucosminexus_application_server_enterprise 07_00 Yes
Application hitachi ucosminexus_application_server_enterprise 07_00 Yes
Application hitachi ucosminexus_application_server_enterprise 07_00 Yes
Application hitachi ucosminexus_application_server_enterprise 07_00_12 Yes
Application hitachi ucosminexus_application_server_enterprise 07_10 Yes
Application hitachi ucosminexus_application_server_enterprise 07_10 Yes
Application hitachi ucosminexus_application_server_enterprise 07_10 Yes
Application hitachi ucosminexus_application_server_enterprise 07_10 Yes
Application hitachi ucosminexus_application_server_enterprise 07_10 Yes
Application hitachi ucosminexus_application_server_enterprise 07_10_1 Yes
Application hitachi ucosminexus_application_server_enterprise 07_10_06 Yes
Application hitachi ucosminexus_application_server_enterprise 07_10_08 Yes
Application hitachi ucosminexus_application_server_standard 06_70 Yes
Application hitachi ucosminexus_application_server_standard 06_70_a Yes
Application hitachi ucosminexus_application_server_standard 06_70_a Yes
Application hitachi ucosminexus_application_server_standard 06_70_b Yes
Application hitachi ucosminexus_application_server_standard 06_70_b Yes
Application hitachi ucosminexus_application_server_standard 06_70_b Yes
Application hitachi ucosminexus_application_server_standard 06_70_b Yes
Application hitachi ucosminexus_application_server_standard 06_70_b_1 Yes
Application hitachi ucosminexus_application_server_standard 06_70_c Yes
Application hitachi ucosminexus_application_server_standard 06_70_d Yes
Application hitachi ucosminexus_application_server_standard 06_71 Yes
Application hitachi ucosminexus_application_server_standard 06_71_b Yes
Application hitachi ucosminexus_application_server_standard 06_72_1 Yes
Application hitachi ucosminexus_application_server_standard 06_72_b_1 Yes
Application hitachi ucosminexus_application_server_standard 06_72_c Yes
Application hitachi ucosminexus_application_server_standard 06_72_d Yes
Application hitachi ucosminexus_application_server_standard 06_72_g Yes
Application hitachi ucosminexus_application_server_standard 07_00 Yes
Application hitachi ucosminexus_application_server_standard 07_00 Yes
Application hitachi ucosminexus_application_server_standard 07_00 Yes
Application hitachi ucosminexus_application_server_standard 07_00 Yes
Application hitachi ucosminexus_application_server_standard 07_00_1 Yes
Application hitachi ucosminexus_application_server_standard 07_10 Yes
Application hitachi ucosminexus_application_server_standard 07_10 Yes
Application hitachi ucosminexus_application_server_standard 07_10 Yes
Application hitachi ucosminexus_application_server_standard 07_10 Yes
Application hitachi ucosminexus_service_platform 07_00 Yes
Application hitachi ucosminexus_service_platform 07_10 Yes
Application hitachi ucosminexus_service_platform 07_10 Yes

References

How SecUtils Interprets This CVE

SecUtils normalizes and enriches National Vulnerability Database (NVD) records by standardizing vendor and product identifiers, aggregating vulnerability metadata from both NVD and MITRE sources, and providing structured context for security teams. For hitachi's affected products, we extract Common Platform Enumeration (CPE) data, Common Weakness Enumeration (CWE) classifications, CVSS severity metrics, and reference data to enable rapid vulnerability prioritization and asset correlation. This record contains no exploit code, proof-of-concept instructions, or attack methodologies—only defensive intelligence necessary for patch management, risk assessment, and security operations.