PT-2020-8678 · Hitachi · Hitachi Global Link Manager+8
Piotr Madej
·
Published
2020-02-14
·
Updated
2020-02-27
·
CVE-2018-21033
CVSS v3.1
6.5
Medium
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N |
Name of the Vulnerable Software and Affected Versions
Hitachi Command Suite versions prior to 8.6.2-00
Hitachi Automation Director versions prior to 8.6.2-00
Hitachi Infrastructure Analytics Advisor versions prior to 4.2.0-00
Description
A vulnerability allows authenticated remote users to load an arbitrary Cascading Style Sheets (CSS) token sequence. This issue affects various components of Hitachi Command Suite, including Hitachi Device Manager, Hitachi Tiered Storage Manager, Hitachi Replication Manager, Hitachi Tuning Manager, Hitachi Global Link Manager, and Hitachi Compute Systems Manager.
Recommendations
For Hitachi Command Suite versions prior to 8.6.2-00, update to version 8.6.2-00 or later.
For Hitachi Automation Director versions prior to 8.6.2-00, update to version 8.6.2-00 or later.
For Hitachi Infrastructure Analytics Advisor versions prior to 4.2.0-00, update to version 4.2.0-00 or later.
Fix
RCE
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Hitachi Automation Director
Hitachi Command Suite
Hitachi Compute Systems Manager
Hitachi Device Manager
Hitachi Global Link Manager
Hitachi Infrastructure Analytics Advisor
Hitachi Replication Manager
Hitachi Tiered Storage Manager
Hitachi Tuning Manager