[Japanese]

JVNDB-2017-003108

Multiple Vulnerabilities in Hitachi IT Operations Director and JP1/IT Desktop Management

Overview

A cross-site scripting and an XML external entity (XXE) vulnerability have been found in Hitachi IT Operations Director, JP1/IT Desktop Management - Manager and JP1/IT Desktop Management 2 - Manager.
CVSS Severity (What is CVSS?)

Base Metrics: 7.5 (High) [Vendor Score]
  • Access Vector: Network
  • Access Complexity: Low
  • Authentication: Single Instance
  • Confidentiality Impact: Partial
  • Integrity Impact: None
  • Availability Impact: Complete

CVSS V3 Severity:
Base Metrics: 8.1 (High) [Vendor Score]
  • Access Vector: Network
  • Attack Complexity: Low
  • Privileges Required: Low
  • User Interaction: None
  • Scope: Unchanged
  • Confidentiality Impact: High
  • Integrity Impact: None
  • Availability Impact: High
Affected Products


Hitachi, Ltd
  • Hitachi IT Operations Director
  • Job Management Partner 1/IT Desktop Management 2 - Manager
  • Job Management Partner 1/IT Desktop Management - Manager
  • JP1/IT Desktop Management 2 - Manager
  • JP1/IT Desktop Management 2 - Operations Director
  • JP1/IT Desktop Management - Manager

Please refer to the vendor information for more details.
Impact

An attacker may conduct a cross-site scripting attack and a XML external entity (XXE) attack.
Solution

Please refer to the 'Vendor Information' section for the official countermeasure and take appropriate action.
Vendor Information

Hitachi, Ltd
CWE (What is CWE?)

  1. No Mapping(CWE-noinfo) [IPA Evaluation]
CVE (What is CVE?)

References

Revision History

[2017/06/30]
  Web page was published