PT-2020-8678 · Hitachi · Hitachi Global Link Manager+8

Piotr Madej

·

Published

2020-02-14

·

Updated

2020-02-27

·

CVE-2018-21033

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N
Name of the Vulnerable Software and Affected Versions Hitachi Command Suite versions prior to 8.6.2-00 Hitachi Automation Director versions prior to 8.6.2-00 Hitachi Infrastructure Analytics Advisor versions prior to 4.2.0-00
Description A vulnerability allows authenticated remote users to load an arbitrary Cascading Style Sheets (CSS) token sequence. This issue affects various components of Hitachi Command Suite, including Hitachi Device Manager, Hitachi Tiered Storage Manager, Hitachi Replication Manager, Hitachi Tuning Manager, Hitachi Global Link Manager, and Hitachi Compute Systems Manager.
Recommendations For Hitachi Command Suite versions prior to 8.6.2-00, update to version 8.6.2-00 or later. For Hitachi Automation Director versions prior to 8.6.2-00, update to version 8.6.2-00 or later. For Hitachi Infrastructure Analytics Advisor versions prior to 4.2.0-00, update to version 4.2.0-00 or later.

Fix

RCE

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2018-21033

Affected Products

Hitachi Automation Director
Hitachi Command Suite
Hitachi Compute Systems Manager
Hitachi Device Manager
Hitachi Global Link Manager
Hitachi Infrastructure Analytics Advisor
Hitachi Replication Manager
Hitachi Tiered Storage Manager
Hitachi Tuning Manager