[Japanese]

JVNDB-2015-006129

Multiple Cross-site Scripting Vulnerabilities in EUR

Overview

Multiple cross-site scripting vulnerabilities were found in EUR.
CVSS Severity (What is CVSS?)

CVSS V2 Severity:
Base Metrics 3.5 (Low) [Vendor Score]
  • Access Vector: Network
  • Access Complexity: Medium
  • Authentication: Single Instance
  • Confidentiality Impact: None
  • Integrity Impact: Partial
  • Availability Impact: None
Affected Products


Hitachi, Ltd
  • EUR Developer
  • EUR Server Enterprise
  • uCosminexus EUR Developer
  • uCosminexus EUR Print Manager - Report Server
  • uCosminexus EUR Server Enterprise

Please refer to HS15-030 provided by Hitachi for more details.
Impact

Remote users can exploit these vulnerabilities to execute malicious scripts.
Solution

Please refer to the 'Vendor Information' section for the official countermeasure and take appropriate action.
Vendor Information

Hitachi, Ltd
  • Hitachi Software Vulnerability Information : HS15-030
CWE (What is CWE?)

  1. Cross-site Scripting(CWE-79) [IPA Evaluation]
CVE (What is CVE?)

References

Revision History

  • [2015/12/17]
      Web page was published
    [2015/12/28]
      CVSS Severity was modified