PT-2015-5354 · Hitachi · Hitachi Device Manager+4

Publicado

2015-02-09

·

Atualizado

2015-02-09

·

CVE-2015-1565

CVSS v2.0

4.3

Média

VetorAV:N/AC:M/Au:N/C:N/I:P/A:N
Name of the Vulnerable Software and Affected Versions Hitachi Device Manager versions prior to 8.1.2-00 Hitachi Tiered Storage Manager versions prior to 8.1.2-00 Hitachi Replication Manager versions prior to 8.1.2-00 Hitachi Global Link Manager versions prior to 8.1.2-00 Hitachi Compute Systems Manager versions prior to 7.6.1-08 and 8.x prior to 8.1.2-00
Description A cross-site scripting (XSS) issue exists in the online help component of the affected software, allowing remote attackers to inject arbitrary web script or HTML. This can be achieved via unspecified vectors.
Recommendations For Hitachi Device Manager versions prior to 8.1.2-00, update to version 8.1.2-00 or later. For Hitachi Tiered Storage Manager versions prior to 8.1.2-00, update to version 8.1.2-00 or later. For Hitachi Replication Manager versions prior to 8.1.2-00, update to version 8.1.2-00 or later. For Hitachi Global Link Manager versions prior to 8.1.2-00, update to version 8.1.2-00 or later. For Hitachi Compute Systems Manager versions prior to 7.6.1-08, update to version 7.6.1-08 or later. For Hitachi Compute Systems Manager versions 8.x prior to 8.1.2-00, update to version 8.1.2-00 or later.

Correção

XSS

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2015-1565

Produtos afetados

Hitachi Compute Systems Manager
Hitachi Device Manager
Hitachi Global Link Manager
Hitachi Replication Manager
Hitachi Tiered Storage Manager