Interstage Application Server: Vulnerability leading to leak of information. November 15th, 2010


Notes on using this web page

1. Description

On a server to which a J2EE application has been deployed and is running, unauthorised file and directory access can be gained.

2. Impact

This vulnerability may be used to gain access to files and directories on the machine.

3. Affected systems and corresponding action

3-1. Affected systems:

GP7000F, PRIMEPOWER, SPARC Enterprise, PRIMERGY, GP5000, CELSIUS, FMV series, AT compatible machines, PRIMEQUEST

3-2. Affected products and required patch

Interstage Application Server
ProductsVersionTarget OSPackage namePatch ID.
Interstage Application Server Enterprise Edition7.0Solaris 8/ 9FJSVjs4*
Interstage Application Server Enterprise Edition7.0Solaris 8/ 9FJSVj2ee*
Interstage Application Server Enterprise Edition7.0.1Solaris 8/ 9/ 10FJSVjs4*
Interstage Application Server Enterprise Edition7.0.1Solaris 8/ 9/ 10FJSVj2ee*
Interstage Application Server Enterprise EditionV8.0.0Solaris 9/ 10FJSVjs4*
Interstage Application Server Enterprise EditionV8.0.0Solaris 9/ 10FJSVj2ee*
Interstage Application Server Enterprise EditionV8.0.2Solaris 9/ 10FJSVjs4*
Interstage Application Server Enterprise EditionV8.0.2Solaris 9/ 10FJSVj2ee*
Interstage Application Server Enterprise EditionV9.0.0Solaris 9/ 10FJSVjs5*
Interstage Application Server Enterprise EditionV9.0.0Solaris 9/ 10FJSVj2ee*
Interstage Application Server Enterprise EditionV9.0.0Solaris 9/ 10FJSVjs4*
Interstage Application Server Enterprise EditionV9.0.0Solaris 9/ 10FJSVj2ee*
Interstage Application Server Standard-J EditionV8.0.0Solaris 9/ 10FJSVjs4*
Interstage Application Server Standard-J EditionV8.0.0Solaris 9/ 10FJSVj2ee*
Interstage Application Server Standard-J EditionV8.0.2Solaris 9/ 10FJSVjs4*
Interstage Application Server Standard-J EditionV8.0.2Solaris 9/ 10FJSVj2ee*
Interstage Application Server Standard-J EditionV9.0.0Solaris 9/ 10FJSVjs5*
Interstage Application Server Standard-J EditionV9.0.0Solaris 9/ 10FJSVj2ee*
Interstage Application Server Standard-J EditionV9.0.0Solaris 9/ 10FJSVjs4*
Interstage Application Server Standard-J EditionV9.0.0Solaris 9/ 10FJSVj2ee*
Interstage Application Server Plus7.0Solaris 8/ 9FJSVjs4*
Interstage Application Server Plus7.0Solaris 8/ 9FJSVj2ee*
Interstage Application Server Plus7.0.1Solaris 8/ 9/ 10FJSVjs4*
Interstage Application Server Plus7.0.1Solaris 8/ 9/ 10FJSVj2ee*
Interstage Application Server Enterprise Edition for WindowsV7.0Windows 2003/ 2000F3FMjs4*
Interstage Application Server Enterprise Edition for WindowsV7.0Windows 2003/ 2000J2EE*
Interstage Application Server Enterprise Edition for WindowsV7.0.1Windows 2003/ 2000F3FMjs4*
Interstage Application Server Enterprise Edition for WindowsV7.0.1Windows 2003/ 2000J2EE*
Interstage Application Server Enterprise Edition for WindowsV8.0.0Windows 2003/ 2000F3FMjs4*
Interstage Application Server Enterprise Edition for WindowsV8.0.0Windows 2003/ 2000J2EE*
Interstage Application Server Enterprise Edition for WindowsV8.0.1Windows 2003/ 2000F3FMjs4*
Interstage Application Server Enterprise Edition for WindowsV8.0.1Windows 2003/ 2000J2EE*
Interstage Application Server Enterprise Edition for WindowsV8.0.2Windows 2003/ 2000F3FMjs4*
Interstage Application Server Enterprise Edition for WindowsV8.0.2Windows 2003/ 2000J2EE*
Interstage Application Server Enterprise Edition for WindowsV9.0.0Windows 2003/ 2000F3FMjs5*
Interstage Application Server Enterprise Edition for WindowsV9.0.0Windows 2003/ 2000J2EE*
Interstage Application Server Enterprise Edition for WindowsV9.0.0Windows 2003/ 2000F3FMjs4*
Interstage Application Server Enterprise Edition for WindowsV9.0.0Windows 2003/ 2000J2EE*
Interstage Application Server Enterprise Edition for WindowsV9.0.0AWindows 2003/ 2000F3FMjs5*
Interstage Application Server Enterprise Edition for WindowsV9.0.0AWindows 2003/ 2000J2EE*
Interstage Application Server Enterprise Edition for WindowsV9.0.0AWindows 2003/ 2000F3FMjs4*
Interstage Application Server Enterprise Edition for WindowsV9.0.0AWindows 2003/ 2000J2EE*
Interstage Application Server Standard-J Edition for WindowsV8.0.0Windows 2003/ 2000F3FMjs4*
Interstage Application Server Standard-J Edition for WindowsV8.0.0Windows 2003/ 2000J2EE*
Interstage Application Server Standard-J Edition for WindowsV8.0.1Windows 2003/ 2000F3FMjs4*
Interstage Application Server Standard-J Edition for WindowsV8.0.1Windows 2003/ 2000J2EE*
Interstage Application Server Standard-J Edition for WindowsV8.0.2Windows 2003/ 2000F3FMjs4*
Interstage Application Server Standard-J Edition for WindowsV8.0.2Windows 2003/ 2000J2EE*
Interstage Application Server Standard-J Edition for WindowsV9.0.0Windows 2003/ 2000F3FMjs5*
Interstage Application Server Standard-J Edition for WindowsV9.0.0Windows 2003/ 2000J2EE*
Interstage Application Server Standard-J Edition for WindowsV9.0.0Windows 2003/ 2000F3FMjs4*
Interstage Application Server Standard-J Edition for WindowsV9.0.0Windows 2003/ 2000J2EE*
Interstage Application Server Standard-J Edition for WindowsV9.0.0AWindows 2003/ 2000F3FMjs5*
Interstage Application Server Standard-J Edition for WindowsV9.0.0AWindows 2003/ 2000J2EE*
Interstage Application Server Standard-J Edition for WindowsV9.0.0AWindows 2003/ 2000F3FMjs4*
Interstage Application Server Standard-J Edition for WindowsV9.0.0AWindows 2003/ 2000J2EE*
Interstage Application Server Plus for WindowsV7.0Windows 2003/ 2000F3FMjs4*
Interstage Application Server Plus for WindowsV7.0Windows 2003/ 2000J2EE*
Interstage Application Server Plus for WindowsV7.0.1Windows 2003/ 2000F3FMjs4*
Interstage Application Server Plus for WindowsV7.0.1Windows 2003/ 2000J2EE*
Interstage Application Server Plus Developer for WindowsV7.0Windows 2003/ 2000/ XPF3FMjs4*
Interstage Application Server Plus Developer for WindowsV7.0Windows 2003/ 2000/ XPJ2EE*
Interstage Application Server Enterprise Edition for WindowsV8.0.0Windows 2003(IPF)F3FMjs4*
Interstage Application Server Enterprise Edition for WindowsV8.0.0Windows 2003(IPF)J2EE*
Interstage Application Server Enterprise Edition for WindowsV9.0.0Windows 2003(IPF)F3FMjs5*
Interstage Application Server Enterprise Edition for WindowsV9.0.0Windows 2003(IPF)J2EE*
Interstage Application Server Enterprise Edition for WindowsV9.0.0Windows 2003(IPF)F3FMjs4*
Interstage Application Server Enterprise Edition for WindowsV9.0.0Windows 2003(IPF)J2EE*
Interstage Application Server Standard-J Edition for WindowsV9.0.0Windows 2003(IPF)F3FMjs5*
Interstage Application Server Standard-J Edition for WindowsV9.0.0Windows 2003(IPF)J2EE*
Interstage Application Server Standard-J Edition for WindowsV9.0.0Windows 2003(IPF)F3FMjs4*
Interstage Application Server Standard-J Edition for WindowsV9.0.0Windows 2003(IPF)J2EE*
Interstage Application Server Enterprise Edition for LinuxV7.0RHEL-AS3(x86)/ ES3(x86)FJSVjs4*
Interstage Application Server Enterprise Edition for LinuxV7.0RHEL-AS3(x86)/ ES3(x86)FJSVj2ee*
Interstage Application Server Enterprise Edition for LinuxV7.0.1RHEL-AS3(x86)/ ES3(x86)FJSVjs4*
Interstage Application Server Enterprise Edition for LinuxV7.0.1RHEL-AS3(x86)/ ES3(x86)FJSVj2ee*
Interstage Application Server Enterprise Edition for LinuxV8.0.0RHEL-AS4(x86)/ AS4(EM64T)FJSVjs4*
Interstage Application Server Enterprise Edition for LinuxV8.0.0RHEL-AS4(x86)/ AS4(EM64T)FJSVj2ee*
Interstage Application Server Enterprise Edition for LinuxV8.0.2RHEL-AS4(x86)/ AS4(EM64T)FJSVjs4*
Interstage Application Server Enterprise Edition for LinuxV8.0.2RHEL-AS4(x86)/ AS4(EM64T)FJSVj2ee*
Interstage Application Server Enterprise Edition for LinuxV9.0.0RHEL-AS4(x86)/ AS4(EM64T)FJSVjs5*
Interstage Application Server Enterprise Edition for LinuxV9.0.0RHEL-AS4(x86)/ AS4(EM64T)FJSVj2ee*
Interstage Application Server Enterprise Edition for LinuxV9.0.0RHEL-AS4(x86)/ AS4(EM64T)FJSVjs4*
Interstage Application Server Enterprise Edition for LinuxV9.0.0RHEL-AS4(x86)/ AS4(EM64T)FJSVj2ee*
Interstage Application Server Enterprise Edition for LinuxV9.0.0RHEL5(x86)/ RHEL5(Intel64)FJSVjs5*
Interstage Application Server Enterprise Edition for LinuxV9.0.0RHEL5(x86)/ RHEL5(Intel64)FJSVj2ee*
Interstage Application Server Standard-J Edition for LinuxV8.0.0RHEL-AS4(x86)/ AS4(EM64T)FJSVjs4*
Interstage Application Server Standard-J Edition for LinuxV8.0.0RHEL-AS4(x86)/ AS4(EM64T)FJSVj2ee*
Interstage Application Server Standard-J Edition for LinuxV8.0.2RHEL-AS4(x86)/ AS4(EM64T)FJSVjs4*
Interstage Application Server Standard-J Edition for LinuxV8.0.2RHEL-AS4(x86)/ AS4(EM64T)FJSVj2ee*
Interstage Application Server Standard-J Edition for LinuxV9.0.0RHEL-AS4(x86)/ AS4(EM64T)FJSVjs5*
Interstage Application Server Standard-J Edition for LinuxV9.0.0RHEL-AS4(x86)/ AS4(EM64T)FJSVj2ee*
Interstage Application Server Standard-J Edition for LinuxV9.0.0RHEL-AS4(x86)/ AS4(EM64T)FJSVjs4*
Interstage Application Server Standard-J Edition for LinuxV9.0.0RHEL-AS4(x86)/ AS4(EM64T)FJSVj2ee*
Interstage Application Server Standard-J Edition for LinuxV9.0.0RHEL5(x86)/ RHEL5(Intel64)FJSVjs5*
Interstage Application Server Standard-J Edition for LinuxV9.0.0RHEL5(x86)/ RHEL5(Intel64)FJSVj2ee*
Interstage Application Server Plus for LinuxV7.0RHEL-AS3(x86)/ ES3(x86)FJSVjs4*
Interstage Application Server Plus for LinuxV7.0RHEL-AS3(x86)/ ES3(x86)FJSVj2ee*
Interstage Application Server Plus for LinuxV7.0.1RHEL-AS3(x86)/ ES3(x86)FJSVjs4*
Interstage Application Server Plus for LinuxV7.0.1RHEL-AS3(x86)/ ES3(x86)FJSVj2ee*
Interstage Application Server Enterprise Edition for LinuxV7.0RHEL-AS4(IPF)FJSVjs4*
Interstage Application Server Enterprise Edition for LinuxV7.0RHEL-AS4(IPF)FJSVj2ee*
Interstage Application Server Enterprise Edition for LinuxV8.0.0RHEL-AS4(IPF)FJSVjs4*
Interstage Application Server Enterprise Edition for LinuxV8.0.0RHEL-AS4(IPF)FJSVj2ee*
Interstage Application Server Enterprise Edition for LinuxV8.0.1RHEL-AS4(IPF)FJSVjs4*
Interstage Application Server Enterprise Edition for LinuxV8.0.1RHEL-AS4(IPF)FJSVj2ee*
Interstage Application Server Enterprise Edition for LinuxV8.0.2RHEL-AS4(IPF)FJSVjs4*
Interstage Application Server Enterprise Edition for LinuxV8.0.2RHEL-AS4(IPF)FJSVj2ee*
Interstage Application Server Enterprise Edition for LinuxV9.0.0RHEL-AS4(IPF)FJSVjs5*
Interstage Application Server Enterprise Edition for LinuxV9.0.0RHEL-AS4(IPF)FJSVj2ee*
Interstage Application Server Enterprise Edition for LinuxV9.0.0RHEL5(IPF)FJSVjs5*
Interstage Application Server Enterprise Edition for LinuxV9.0.0RHEL5(IPF)FJSVj2ee*
Interstage Application Server Enterprise Edition for LinuxV9.0.0RHEL-AS4(IPF)FJSVjs4*
Interstage Application Server Enterprise Edition for LinuxV9.0.0RHEL-AS4(IPF)FJSVj2ee*
Interstage Application Server Enterprise Edition for LinuxV9.0.0ARHEL-AS4(IPF)FJSVjs5*
Interstage Application Server Enterprise Edition for LinuxV9.0.0ARHEL-AS4(IPF)FJSVj2ee*
Interstage Application Server Enterprise Edition for LinuxV9.0.0ARHEL5(IPF)FJSVjs5*
Interstage Application Server Enterprise Edition for LinuxV9.0.0ARHEL5(IPF)FJSVj2ee*
Interstage Application Server Enterprise Edition for LinuxV9.0.0ARHEL-AS4(IPF)FJSVjs4*
Interstage Application Server Enterprise Edition for LinuxV9.0.0ARHEL-AS4(IPF)FJSVj2ee*
Interstage Application Server Standard-J Edition for LinuxV9.0.0RHEL-AS4(IPF)FJSVjs5*
Interstage Application Server Standard-J Edition for LinuxV9.0.0RHEL-AS4(IPF)FJSVj2ee*
Interstage Application Server Standard-J Edition for LinuxV9.0.0RHEL5(IPF)FJSVjs5*
Interstage Application Server Standard-J Edition for LinuxV9.0.0RHEL5(IPF)FJSVj2ee*
Interstage Application Server Standard-J Edition for LinuxV9.0.0RHEL-AS4(IPF)FJSVjs4*
Interstage Application Server Standard-J Edition for LinuxV9.0.0RHEL-AS4(IPF)FJSVj2ee*
Interstage Apworks/Studio
ProductsVersionTarget OSPackage namePatch ID.
Interstage Apworks Modelers-J Edition for WindowsV7.0Windows 2003/ 2000/ XPF3FMjs4*
Interstage Apworks Modelers-J Edition for WindowsV7.0Windows 2003/ 2000/ XPJ2EE*
Interstage Studio Enterprise Edition for Windows8.0.1Windows 2003/ 2000/ XPF3FMjs4*
Interstage Studio Enterprise Edition for Windows8.0.1Windows 2003/ 2000/ XPJ2EE*
Interstage Studio Enterprise Edition for Windows9.0.0Windows 2003/ 2000/ XP/ VistaF3FMjs5*
Interstage Studio Enterprise Edition for Windows9.0.0Windows 2003/ 2000/ XP/ VistaJ2EE*
Interstage Studio Standard-J Edition for Windows8.0.1Windows 2003/ 2000/ XPF3FMjs4*
Interstage Studio Standard-J Edition for Windows8.0.1Windows 2003/ 2000/ XPJ2EE*
Interstage Studio Standard-J Edition for Windows9.0.0Windows 2003/ 2000/ XP/ VistaF3FMjs5*
Interstage Studio Standard-J Edition for Windows9.0.0Windows 2003/ 2000/ XP/ VistaJ2EE*
Interstage Business Application Server
ProductsVersionTarget OSPackage namePatch ID.
Interstage Business Application Server Enterprise Edition for Linux8.0.0RHEL-AS4(IPF)FJSVjs4*
Interstage Business Application Server Enterprise Edition for Linux8.0.0RHEL-AS4(IPF)FJSVj2ee*
Interstage Job Workload Server
ProductsVersionTarget OSPackage namePatch ID.
Interstage Job Workload Server for Linux8.1.0RHEL-AS4(IPF)FJSVjs4*
Interstage Job Workload Server for Linux8.1.0RHEL-AS4(IPF)FJSVj2ee*


* For the Patches without ID nor link, please contact a Fujitsu system engineer or your partner(s).

Note: Determining the affected product

  • [V7 series or later]
    Use the isprintvl command.
      isprintvl

3-3. Workaround

None.

4. Related information

None.

5. Revision history

  • November 15th, 2010: Initial release

Top of Page