Vulnerability description
Cosminexus Developer's Kit for Java(TM) and Hitachi Developer's Kit for Java contain the following vulnerabilities:
CVE-2024-21208, CVE-2024-21210, CVE-2024-21217, CVE-2024-21235
Affected products and versions are listed below. Please upgrade your version to the appropriate version.
These vulnerabilities exist in Cosminexus Developer's Kit for Java(TM) amd, Hitachi Developer's Kit for Java which is a component product of other Hitachi products.
For details about the fixed version about Cosminexus products, contact your Hitachi support service representative.
Affected products
The information is organized under the following headings:
(Example)
Product name: Gives the name of the affected product.
Version:
- Platform
- Gives the affected version.
- Cosminexus V11
Product name: uCosminexus Application Server
Product name: uCosminexus Application Server(64)
Product name: uCosminexus Application Server-R
Product name: uCosminexus Client
Product name: uCosminexus Developer
Product name: uCosminexus Service Architect
Product name: uCosminexus Service Platform
Product name: uCosminexus Service Platform(64)
Product name: uCosminexus Primary Server Base
Product name: uCosminexus Primary Server Base(64)
Version(s):
- Windows
- 11-00 to 11-50
- Linux
- 11-00 to 11-40
- AIX
- 11-00 to 11-00-02
- Cosminexus V9(*1)
Product name: uCosminexus Application Server
Product name: uCosminexus Application Server(64)
Product name: uCosminexus Application Server-R
Product name: uCosminexus Client
Product name: uCosminexus Developer
Product name: uCosminexus Service Architect
Product name: uCosminexus Service Platform
Product name: uCosminexus Service Platform(64)
Product name: uCosminexus Primary Server Base
Product name: uCosminexus Primary Server Base(64)
Product name: uCosminexus Operator for Service Platform
Version(s):
- Windows
- 09-70 to 09-70-02
- Windows(x64)
- 09-70 to 09-87-01
- Linux
- 09-70 to 09-87-01
- AIX
- 09-70 to 09-70-01
- *1
- Vulnerabilitiy impact for versions 09-80 and prior to 09-60 (including V8), no information available for disclosure due to the EOL (End of Life) of the software components.
Please contact your Hitachi support service representative or consider migrating to a fixed version for preventive maintenance.
- uCosminexus Application Runtime
Product name: uCosminexus Application Runtime with Java for Apache Tomcat
Product name: uCosminexus Application Runtime with Java for Spring Boot
Version(s):
- Linux(x64)
- 01-00 to 01-10
- Hitachi Application Server
Product name: Hitachi Application Server
Product name: Hitachi Application Server for Developers
Version(s):
- Windows
- 10-10 to 10-10-04
- Windows(x64)
- 10-10 to 10-11-05
- Linux(x64)
- 10-11 to 10-11-04
Fixed products
The information is organized under the following headings:
(Example)
Product name: Gives the name of the fixed product.
Version:
- Platform
- Gives the fixed version.
Scheduled version:
- Platform
- Gives the fixed version scheduled to be released.
Product name: Cosminexus Developer's Kit for Java(TM)
Version(s):
- Windows(x64)
- 11-40-01
- 11-30-01
- 09-87-39
- Linux(x64)
- 11-40-01
- 11-30-01
- 09-88-39
- 09-87-39
Product name: Hitachi Developer's Kit for Java
Scheduled Version(s):
For details on the fixed products, contact your Hitachi support service representative.