PT-2022-9881 · Hitachi · Hitachi Content Platform

Published

2022-09-26

·

Updated

2022-09-28

·

CVE-2021-28052

CVSS v3.1

7.5

High

VectorAV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Hitachi Content Platform versions prior to 8.3.7 Hitachi Content Platform 9.0.0 versions prior to 9.2.3
Description A tenant administrator of Hitachi Content Platform (HCP) may modify the configuration in another tenant without authorization, potentially allowing unauthorized access to data in the other tenant. Additionally, a tenant user (non-administrator) may view configuration in another tenant without authorization.
Recommendations For versions prior to 8.3.7, update to version 8.3.7 or later. For 9.0.0 versions prior to 9.2.3, update to version 9.2.3 or later.

Fix

Missing Authorization

Weakness Enumeration

Related Identifiers

CVE-2021-28052

Affected Products

Hitachi Content Platform