掲載番号:NV09-011
脆弱性情報識別番号:CVE-2008-0128
Apache Tomcat JSESSIONIDSSOクッキーの不適切な設定の問題
概要
Apache Tomcatには、JSESSIONIDSSOクッキーの不適切な設定によりhttpリクエストを送信する際に、SingleSignOn用のクッキーを使用する問題が存在します。
そのため第三者によりSingleSignOn用のクッキーを盗聴される可能性があります。
対象製品
WebOTX Application Server
- 対処方法
対象となる製品のバージョン:
- WebOTX Web Edition V4.x〜V6.x
- WebOTX Standard-J Edition V4.x〜V6.x
- WebOTX Standard Edition V4.x〜V6.x
- WebOTX Enterprise Edition V4.x〜V6.x
- WebOTX Application Server Web Edition V7.x〜V8.1
- WebOTX Application Server Standard-J Edition V7.x〜V8.1
- WebOTX Application Server Standard Edition V7.x〜V8.1
- WebOTX Application Server Enterprise Edition V7.x〜V8.1
- WebOTX UDDI Registry V1.1〜V7.1
- WebOTX 開発環境 V6.x
- WebOTX Developer V7.x〜V8.1
- WebOTX Enterprise Service Bus V6.4〜V7.x
- WebOTX SIP Application Server Standard Edition V7.x〜V8.1
別途パッチを用意しております。詳細につきましては弊社営業にお問合せください。
参考情報
更新情報