- Fujitsu Patch & TA Information
- Oracle Solaris Patch & TA Information
There is a buffer overflow vulnerability in the Interstage Application Server Single Sign-on function.
For details on how to avoid the problem please refer to section 3, below.
The vulnerability may allow a internet attacker (malicious third party) who issues a particular request to the Single Sign-on authentication server to execute arbitrary code or cause a Denial of Service (DoS).
GP7000F, PRIMEPOWER, PRIMERGY, GP5000, CELSIUS, FMV series, AT-compatible machine, PRIMEQUEST, SPARC Enterprise
Note: The values set in "Workaround" below depend on the product. The symbol in square brackets after 'Product' corresponds to the contents set of "Workaround".
| Products | Target OS | Package name | Patch ID. |
|---|---|---|---|
| Interstage Application Server Enterprise Edition 8.0.0 for Windows [a] | Windows | FJSVsso | * |
| Interstage Application Server Standard-J Edition 8.0.0 for Windows [a] | Windows | FJSVsso | * |
| Interstage Application Server Enterprise Edition 8.0.1 for Windows [a] | Windows | FJSVsso | * |
| Interstage Application Server Standard-J Edition 8.0.1 for Windows [a] | Windows | FJSVsso | * |
| Interstage Application Server Enterprise Edition 8.0.2 for Windows [a] | Windows | FJSVsso | * |
| Interstage Application Server Standard-J Edition 8.0.2 for Windows [a] | Windows | FJSVsso | * |
| Interstage Application Server Enterprise Edition 8.0.3 for Windows [a] | Windows | FJSVsso | * |
| Interstage Application Server Standard-J Edition 8.0.3 for Windows [a] | Windows | FJSVsso | * |
| Interstage Application Server Enterprise Edition V9.0.0 for Windows [b] | Windows | FJSVsso | * |
| Interstage Application Server Standard-J Edition V9.0.0 for Windows [b] | Windows | FJSVsso | * |
| Interstage Application Server Enterprise Edition V9.0.0A for Windows [b] | Windows | FJSVsso | * |
| Interstage Application Server Standard-J Edition V9.0.0A for Windows [b] | Windows | FJSVsso | * |
| Interstage Application Server Enterprise Edition 8.0.0 [c] | Solaris | FJSVssoac | * |
| Interstage Application Server Standard-J Edition 8.0.0 [c] | Solaris | FJSVssoac | * |
| Interstage Application Server Enterprise Edition 8.0.2 [c] | Solaris | FJSVssoac | * |
| Interstage Application Server Standard-J Edition 8.0.2 [c] | Solaris | FJSVssoac | * |
| Interstage Application Server Enterprise Edition 8.0.3 [c] | Solaris | FJSVssoac | * |
| Interstage Application Server Standard-J Edition 8.0.3 [c] | Solaris | FJSVssoac | * |
| Interstage Application Server Enterprise Edition V9.0.0 [d] | Solaris | FJSVssoac | * |
| Interstage Application Server Standard-J Edition V9.0.0 [d] | Solaris | FJSVssoac | * |
| Interstage Application Server Enterprise Edition 8.0.0 [c] | RHEL-AS4(x86)/ AS4(EM64T) | FJSVssoac | * |
| Interstage Application Server Standard-J Edition 8.0.0 [c] | RHEL-AS4(x86)/ AS4(EM64T) | FJSVssoac | * |
| Interstage Application Server Enterprise Edition 8.0.2 [c] | RHEL-AS4(x86)/ AS4(EM64T) | FJSVssoac | * |
| Interstage Application Server Standard-J Edition 8.0.2 [c] | RHEL-AS4(x86)/ AS4(EM64T) | FJSVssoac | * |
| Interstage Application Server Enterprise Edition 8.0.3 [c] | RHEL-AS4(x86)/ AS4(EM64T) | FJSVssoac | * |
| Interstage Application Server Standard-J Edition 8.0.3 [c] | RHEL-AS4(x86)/ AS4(EM64T) | FJSVssoac | * |
| Interstage Application Server Enterprise Edition V9.0.0 [d] | RHEL-AS4(x86)/ AS4(EM64T) | FJSVssoac | * |
| Interstage Application Server Enterprise Edition V9.0.0 [d] | RHEL5(x86)/ RHEL5(Intel64) | FJSVssoac | * |
| Interstage Application Server Standard-J Edition V9.0.0 [d] | RHEL-AS4(x86)/ AS4(EM64T) | FJSVssoac | * |
| Interstage Application Server Standard-J Edition V9.0.0 [d] | RHEL5(x86)/ RHEL5(Intel64) | FJSVssoac | * |
| Interstage Application Server Enterprise Edition V9.0.0 [d] | RHEL-AS4(IPF) | FJSVssoac | * |
| Interstage Application Server Enterprise Edition V9.0.0 [d] | RHEL5(IPF) | FJSVssoac | * |
| Interstage Application Server Standard-J Edition V9.0.0 [d] | RHEL-AS4(IPF) | FJSVssoac | * |
| Interstage Application Server Standard-J Edition V9.0.0 [d] | RHEL5(IPF) | FJSVssoac | * |
| Interstage Application Server Enterprise Edition V9.0.0A [d] | RHEL-AS4(IPF) | FJSVssoac | * |
| Interstage Application Server Enterprise Edition V9.0.0A [d] | RHEL5(IPF) | FJSVssoac | * |
| Products | Target OS | Package name | Patch ID. |
|---|---|---|---|
| Interstage Studio Enterprise Edition 8.0.1 for Windows [a] | Windows | FJSVsso | * |
| Interstage Studio Standard-J Edition 8.0.1 for Windows [a] | Windows | FJSVsso | * |
| Interstage Studio Enterprise Edition V9.0.0 for Windows [b] | Windows | FJSVsso | * |
| Interstage Studio Standard-J Edition V9.0.0 for Windows [b] | Windows | FJSVsso | * |
* For the Patches without ID nor link, please contact a Fujitsu system engineer or your partner(s).
Until this patch can be applied, the effects of this vulnerability can be avoided as shown below.
Edit the Interstage HTTP Server environment definition file (httpd.conf) that is used for running the Single Sign-on authentication server as shown below.
Use a maximum of 2000 bytes for the request URI length. Then restart the Interstage HTTP Server that is used for running the authentication server.