|
[Japanese]
|
JVNDB-2026-032928
|
Vulnerability in Cosminexus Component Container
|
Cosminexus Service Coordinator, which uses the SOAP communication infrastructure of Cosminexus Component Container, contains an XXE (XML External Entity) vulnerability in user-defined reception services (SOAP reception services) or SOAP adapters operating in SOAP 1.1 mode.
|
CVSS V3 Severity: Base Metrics 7.4 (High) [Vendor Score]
- Attack Vector: Network
- Attack Complexity: High
- Privileges Required: None
- User Interaction: None
- Scope: Unchanged
- Confidentiality Impact: High
- Integrity Impact: None
- Availability Impact: High
|
|
Hitachi, Ltd
- uCosminexus Service Architect Windows(x64) 11-00 - 11-70
- uCosminexus Service Architect Linux 11-00 - 11-70
- uCosminexus Service Architect AIX 11-00
- uCosminexus Service Architect Windows 09-00 - 09-70
- uCosminexus Service Architect Windows(x64) 09-00 - 09-87
- uCosminexus Service Architect Linux 09-00 - 09-87
- uCosminexus Service Architect HP-UX(IPF) 09-00 - 09-50
- uCosminexus Service Architect AIX 09-00 - 09-70
- uCosminexus Service Platform Windows(x64) 11-00 - 11-70
- uCosminexus Service Platform Linux 11-00 - 11-70
- uCosminexus Service Platform AIX 11-00
- uCosminexus Service Platform Windows 09-00 - 09-70
- uCosminexus Service Platform Windows(x64) 09-00 - 09-87
- uCosminexus Service Platform Linux 09-00 - 09-87
- uCosminexus Service Platform HP-UX(IPF) 09-00 - 09-50
- uCosminexus Service Platform AIX 09-00 - 09-70
- uCosminexus Service Platform(64) Windows(x64) 11-00 - 11-70
- uCosminexus Service Platform(64) Linux 11-00 - 11-70
- uCosminexus Service Platform(64) AIX 11-00
- uCosminexus Service Platform(64) Windows 09-00 - 09-70
- uCosminexus Service Platform(64) Windows(x64) 09-00 - 09-87
- uCosminexus Service Platform(64) Linux 09-00 - 09-87
- uCosminexus Service Platform(64) HP-UX(IPF) 09-00 - 09-50
- uCosminexus Service Platform(64) AIX 09-00 - 09-70
|
Please refer to Vendor Information for more details.
|
Regarding the impact of the vulnerability, please refer to the vendor advisory.
|
Please refer to the 'Vendor Information' section for the official countermeasure and take appropriate action.
|
Hitachi, Ltd
|
|
- CVE-2026-71375
|
|
- [2026/09/14]
Web page was published
|