Search
Find a vulnerability
Search criteria
5 vulnerabilities by NTT DATA
JVNDB-2022-000088
Vulnerability from jvndb - Published: 2022-11-14 07:45 - Updated:2024-06-06 07:11
Severity
Summary
TERASOLUNA Global Framework and TERASOLUNA Server Framework for Java (Rich) vulnerable to ClassLoader manipulation
Details
The past versions of TERASOLUNA Global Framework and TERASOLUNA Server Framework for Java (Rich) are vulnerable to a ClassLoader manipulation vulnerability due to using the old version of Spring Framework which contains the vulnerability.
According to the developer, this vulnerability is caused by an improper input validation issue (CWE-20) in the binding mechanism of Spring MVC.
NTT DATA Corporation reported this vulnerability to IPA to notify users of its solution through JVN. JPCERT/CC and NTT DATA Corporation coordinated under the Information Security Early Warning Partnership.
References
| Type | URL | ||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
|||||||||||||||||
Impacted products
{
"@rdf:about": "https://jvndb.jvn.jp/en/contents/2022/JVNDB-2022-000088.html",
"dc:date": "2024-06-06T16:11+09:00",
"dcterms:issued": "2022-11-14T16:45+09:00",
"dcterms:modified": "2024-06-06T16:11+09:00",
"description": "The past versions of TERASOLUNA Global Framework and TERASOLUNA Server Framework for Java (Rich) are vulnerable to a ClassLoader manipulation vulnerability due to using the old version of Spring Framework which contains the vulnerability.\r\nAccording to the developer, this vulnerability is caused by an improper input validation issue (CWE-20) in the binding mechanism of Spring MVC.\r\n\r\nNTT DATA Corporation reported this vulnerability to IPA to notify users of its solution through JVN. JPCERT/CC and NTT DATA Corporation coordinated under the Information Security Early Warning Partnership.",
"link": "https://jvndb.jvn.jp/en/contents/2022/JVNDB-2022-000088.html",
"sec:cpe": [
{
"#text": "cpe:/a:nttdata:terasoluna_global_framework",
"@product": "TERASOLUNA Global Framework",
"@vendor": "NTT DATA",
"@version": "2.2"
},
{
"#text": "cpe:/a:nttdata:terasoluna_server_framework_for_java_%28rich%29",
"@product": "TERASOLUNA Server Framework for Java (Rich)",
"@vendor": "NTT DATA",
"@version": "2.2"
}
],
"sec:cvss": [
{
"@score": "7.5",
"@severity": "High",
"@type": "Base",
"@vector": "AV:N/AC:L/Au:N/C:P/I:P/A:P",
"@version": "2.0"
},
{
"@score": "9.8",
"@severity": "Critical",
"@type": "Base",
"@vector": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
"@version": "3.0"
}
],
"sec:identifier": "JVNDB-2022-000088",
"sec:references": [
{
"#text": "https://jvn.jp/en/jp/JVN54728399/index.html",
"@id": "JVN#54728399",
"@source": "JVN"
},
{
"#text": "https://www.cve.org/CVERecord?id=CVE-2022-43484",
"@id": "CVE-2022-43484",
"@source": "CVE"
},
{
"#text": "https://nvd.nist.gov/vuln/detail/CVE-2022-43484",
"@id": "CVE-2022-43484",
"@source": "NVD"
},
{
"#text": "https://github.com/spring-projects/spring-framework/issues/15724",
"@id": "Minor issue with fix for CVE 2010-1622 [SPR-11098] #15724",
"@source": "Related document"
},
{
"#text": "https://www.ipa.go.jp/en/security/vulnerabilities/cwe.html",
"@id": "CWE-20",
"@title": "Improper Input Validation(CWE-20)"
}
],
"title": "TERASOLUNA Global Framework and TERASOLUNA Server Framework for Java (Rich) vulnerable to ClassLoader manipulation"
}
JVNDB-2020-000007
Vulnerability from jvndb - Published: 2020-01-28 06:59 - Updated:2020-01-28 06:59
Severity
Summary
Android App "MyPallete" vulnerable to improper server certificate verification
Details
Android App "MyPallete" developed by NTT Data Corporation is used by several financial institutions as Android applications for their customers.
"MyPallete" is vulnerable to improper server certificate verification (CWE-295) and to improper host-matching validation (CWE-297).
Dai Nakamura of Cryptography Laboratory,Department of Information and Communication Engineering,Tokyo Denki University reported this vulnerability to IPA.
JPCERT/CC coordinated with the developer under Information Security Early Warning Partnership.
References
Impacted products
| Vendor | Product | |
|---|---|---|
{
"@rdf:about": "https://jvndb.jvn.jp/en/contents/2020/JVNDB-2020-000007.html",
"dc:date": "2020-01-28T15:59+09:00",
"dcterms:issued": "2020-01-28T15:59+09:00",
"dcterms:modified": "2020-01-28T15:59+09:00",
"description": "Android App \"MyPallete\" developed by NTT Data Corporation is used by several financial institutions as Android applications for their customers.\r\n\"MyPallete\" is vulnerable to improper server certificate verification (CWE-295) and to improper host-matching validation (CWE-297).\r\n\r\nDai Nakamura of Cryptography Laboratory,Department of Information and Communication Engineering,Tokyo Denki University reported this vulnerability to IPA.\r\nJPCERT/CC coordinated with the developer under Information Security Early Warning Partnership.",
"link": "https://jvndb.jvn.jp/en/contents/2020/JVNDB-2020-000007.html",
"sec:cpe": [
{
"#text": "cpe:/a:misc:multiple_vendors",
"@product": "(Multiple Products)",
"@vendor": "(Multiple Venders)",
"@version": "2.2"
},
{
"#text": "cpe:/a:nttdata:mypallete",
"@product": "MyPallete",
"@vendor": "NTT DATA",
"@version": "2.2"
}
],
"sec:cvss": [
{
"@score": "4.0",
"@severity": "Medium",
"@type": "Base",
"@vector": "AV:N/AC:H/Au:N/C:P/I:P/A:N",
"@version": "2.0"
},
{
"@score": "4.8",
"@severity": "Medium",
"@type": "Base",
"@vector": "CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N",
"@version": "3.0"
}
],
"sec:identifier": "JVNDB-2020-000007",
"sec:references": [
{
"#text": "https://jvn.jp/en/jp/JVN28845872/index.html",
"@id": "JVN#28845872",
"@source": "JVN"
},
{
"#text": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-5523",
"@id": "CVE-2020-5523",
"@source": "CVE"
},
{
"#text": "https://nvd.nist.gov/vuln/detail/CVE-2020-5523",
"@id": "CVE-2020-5523",
"@source": "NVD"
},
{
"#text": "https://www.ipa.go.jp/en/security/vulnerabilities/cwe.html",
"@id": "CWE-Other",
"@title": "No Mapping(CWE-Other)"
}
],
"title": "Android App \"MyPallete\" vulnerable to improper server certificate verification"
}
JVNDB-2016-000098
Vulnerability from jvndb - Published: 2016-06-07 07:26 - Updated:2016-06-27 02:32
Severity
Summary
TERASOLUNA Server Framework for Java(WEB) access restriction bypass vulnerability in the file extention filter
Details
The TERASOLUNA Server Framework for Java(WEB) provided by NTT Data Corporation is a software framework for creating web applications. The TERASOLUNA Server Framework for Java(WEB) has a function to restrict access to contents with specified file extentions from browser requests. This function may be bypassed when a specially crafted path is received.
NTT Data Corporation reported this vulnerability to JPCERT/CC to notify users of its solution through JVN. JPCERT/CC and NTT Data Corporation coordinated under the Information Security Early Warning Partnership.
References
Impacted products
| Vendor | Product | |
|---|---|---|
{
"@rdf:about": "https://jvndb.jvn.jp/en/contents/2016/JVNDB-2016-000098.html",
"dc:date": "2016-06-27T11:32+09:00",
"dcterms:issued": "2016-06-07T16:26+09:00",
"dcterms:modified": "2016-06-27T11:32+09:00",
"description": "The TERASOLUNA Server Framework for Java(WEB) provided by NTT Data Corporation is a software framework for creating web applications. The TERASOLUNA Server Framework for Java(WEB) has a function to restrict access to contents with specified file extentions from browser requests. This function may be bypassed when a specially crafted path is received.\r\n\r\nNTT Data Corporation reported this vulnerability to JPCERT/CC to notify users of its solution through JVN. JPCERT/CC and NTT Data Corporation coordinated under the Information Security Early Warning Partnership.",
"link": "https://jvndb.jvn.jp/en/contents/2016/JVNDB-2016-000098.html",
"sec:cpe": {
"#text": "cpe:/a:nttdata:terasoluna_server_framework_for_java_web",
"@product": "TERASOLUNA Server Framework for Java(Web)",
"@vendor": "NTT DATA",
"@version": "2.2"
},
"sec:cvss": [
{
"@score": "4.3",
"@severity": "Medium",
"@type": "Base",
"@vector": "AV:N/AC:M/Au:N/C:P/I:N/A:N",
"@version": "2.0"
},
{
"@score": "3.7",
"@severity": "Low",
"@type": "Base",
"@vector": "CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N",
"@version": "3.0"
}
],
"sec:identifier": "JVNDB-2016-000098",
"sec:references": [
{
"#text": "http://jvn.jp/en/jp/JVN74659077/index.html",
"@id": "JVN#74659077",
"@source": "JVN"
},
{
"#text": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-1183",
"@id": "CVE-2016-1183",
"@source": "CVE"
},
{
"#text": "https://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2016-1183",
"@id": "CVE-2016-1183",
"@source": "NVD"
},
{
"#text": "https://www.ipa.go.jp/en/security/vulnerabilities/cwe.html",
"@id": "CWE-264",
"@title": "Permissions(CWE-264)"
}
],
"title": "TERASOLUNA Server Framework for Java(WEB) access restriction bypass vulnerability in the file extention filter"
}
JVNDB-2015-000042
Vulnerability from jvndb - Published: 2015-03-24 05:10 - Updated:2016-08-26 07:37Summary
The Validator in TERASOLUNA Server Framework for Java(WEB) vulnerable to input validation bypass
Details
The TERASOLUNA Server Framework for Java(WEB) provided by NTT Data Corporation is a software framework for creating web applications. The TERASOLUNA Server Framework for Java(WEB) is vulnerable to an issue contained in the Apache Struts 1 Validator, since it uses Apache Struts 1.2.9.
The Validator in Apache Struts 1.1 and later contains a function (MPV -- Multi Page Validator) to efficiently define rules for input validation across multiple pages during screen transitions.
The MPV contains a vulnerability where input validation may be bypassed.
When the Apache Struts 1 Validator is used, the web application may be vulnerable even when the MPV is not used explicitly.
References
| Type | URL | |
|---|---|---|
Impacted products
| Vendor | Product | |
|---|---|---|
{
"@rdf:about": "https://jvndb.jvn.jp/en/contents/2015/JVNDB-2015-000042.html",
"dc:date": "2016-08-26T16:37+09:00",
"dcterms:issued": "2015-03-24T14:10+09:00",
"dcterms:modified": "2016-08-26T16:37+09:00",
"description": "The TERASOLUNA Server Framework for Java(WEB) provided by NTT Data Corporation is a software framework for creating web applications. The TERASOLUNA Server Framework for Java(WEB) is vulnerable to an issue contained in the Apache Struts 1 Validator, since it uses Apache Struts 1.2.9.\r\n\r\nThe Validator in Apache Struts 1.1 and later contains a function (MPV -- Multi Page Validator) to efficiently define rules for input validation across multiple pages during screen transitions.\r\nThe MPV contains a vulnerability where input validation may be bypassed.\r\nWhen the Apache Struts 1 Validator is used, the web application may be vulnerable even when the MPV is not used explicitly.",
"link": "https://jvndb.jvn.jp/en/contents/2015/JVNDB-2015-000042.html",
"sec:cpe": {
"#text": "cpe:/a:nttdata:terasoluna_server_framework_for_java_web",
"@product": "TERASOLUNA Server Framework for Java(Web)",
"@vendor": "NTT DATA",
"@version": "2.2"
},
"sec:cvss": {
"@score": "4.3",
"@severity": "Medium",
"@type": "Base",
"@vector": "AV:N/AC:M/Au:N/C:N/I:P/A:N",
"@version": "2.0"
},
"sec:identifier": "JVNDB-2015-000042",
"sec:references": [
{
"#text": "http://jvn.jp/en/jp/JVN86448949/index.html",
"@id": "JVN#86448949",
"@source": "JVN"
},
{
"#text": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-0899",
"@id": "CVE-2015-0899",
"@source": "CVE"
},
{
"#text": "https://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2015-0899",
"@id": "CVE-2015-0899",
"@source": "NVD"
},
{
"#text": "https://www.ipa.go.jp/en/security/vulnerabilities/cwe.html",
"@id": "CWE-20",
"@title": "Improper Input Validation(CWE-20)"
}
],
"title": "The Validator in TERASOLUNA Server Framework for Java(WEB) vulnerable to input validation bypass"
}
JVNDB-2014-000056
Vulnerability from jvndb - Published: 2014-06-17 06:01 - Updated:2015-01-22 06:50Summary
TERASOLUNA Server Framework for Java(Web) vulnerable to ClassLoader manipulation
Details
TERASOLUNA Server Framework for Java(Web) provided by NTT DATA Corporation is a software framework for creating Java web applications. TERASOLUNA Server Framework for Java(Web) bundles Apache Struts 1.2.9, which contains a vulnerability where the ClassLoader may be manipulated (CVE-2014-0114). Therefore, this vulnerability affects TERASOLUNA Server Framework for Java(Web) as well.
References
Impacted products
| Vendor | Product | |
|---|---|---|
{
"@rdf:about": "https://jvndb.jvn.jp/en/contents/2014/JVNDB-2014-000056.html",
"dc:date": "2015-01-22T15:50+09:00",
"dcterms:issued": "2014-06-17T15:01+09:00",
"dcterms:modified": "2015-01-22T15:50+09:00",
"description": "TERASOLUNA Server Framework for Java(Web) provided by NTT DATA Corporation is a software framework for creating Java web applications. TERASOLUNA Server Framework for Java(Web) bundles Apache Struts 1.2.9, which contains a vulnerability where the ClassLoader may be manipulated (CVE-2014-0114). Therefore, this vulnerability affects TERASOLUNA Server Framework for Java(Web) as well.",
"link": "https://jvndb.jvn.jp/en/contents/2014/JVNDB-2014-000056.html",
"sec:cpe": {
"#text": "cpe:/a:nttdata:terasoluna_server_framework_for_java_web",
"@product": "TERASOLUNA Server Framework for Java(Web)",
"@vendor": "NTT DATA",
"@version": "2.2"
},
"sec:cvss": {
"@score": "7.5",
"@severity": "High",
"@type": "Base",
"@vector": "AV:N/AC:L/Au:N/C:P/I:P/A:P",
"@version": "2.0"
},
"sec:identifier": "JVNDB-2014-000056",
"sec:references": [
{
"#text": "http://jvn.jp/en/jp/JVN30962312/index.html",
"@id": "JVN#30962312",
"@source": "JVN"
},
{
"#text": "http://jvndb.jvn.jp/ja/contents/2014/JVNDB-2014-002308.html",
"@id": "JVNDB-2014-002308",
"@source": "JVN iPedia"
},
{
"#text": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-0114",
"@id": "CVE-2014-0114",
"@source": "CVE"
},
{
"#text": "http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2014-0114",
"@id": "CVE-2014-0114",
"@source": "NVD"
},
{
"#text": "https://www.ipa.go.jp/en/security/vulnerabilities/cwe.html",
"@id": "CWE-DesignError",
"@title": "No Mapping(CWE-DesignError)"
}
],
"title": "TERASOLUNA Server Framework for Java(Web) vulnerable to ClassLoader manipulation"
}