PT-2021-6946 · Hitachi · Hitachi Content Platform Anywhere
Published
2021-09-29
·
Updated
2021-10-07
·
CVE-2021-41573
CVSS v2.0
7.8
High
| Vector | AV:N/AC:L/Au:N/C:C/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Hitachi Content Platform Anywhere (HCP-AW) versions 4.4.5 and later
Description
The issue is related to insufficient protection of registration data, which may allow a remote attacker to gain unauthorized access to protected information. If an authenticated user creates a link to a file or folder while the system is running version 4.3.x or earlier, shares the link, and then deletes the file or folder without deleting the link before it expires, a malicious user with the link could browse and download all files of the authenticated user who created the link after the system has been upgraded to version 4.4.5 or 4.5.0.
Recommendations
For Hitachi Content Platform Anywhere (HCP-AW) versions 4.4.5 and later, consider deleting links to files or folders when they are deleted to prevent information disclosure. As a temporary workaround, restrict access to shared links to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Files Accessible to External Parties
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Hitachi Content Platform Anywhere