Vector: | Remote |
Severity: | Low |
Patch: | Patched |
Impact: | Cross-site Scripting (XSS) |
Software: |
Hitachi Compute Systems Manager Software 7.x Hitachi Device Manager Software 8.x Hitachi Global Link Manager 8.x Hitachi Replication Manager 8.x Hitachi Tiered Storage Manager 8.x |
A cross-site scripting vulnerability was found in Hitachi Command Suite.
Vulnerability is caused by an unspecified input validation error. A remote attacker can send a specially crafted HTTP request to the vulnerable application and execute arbitrary html and scripting code in user`s browser in context of a vulnerable website.
Further exploitation of this vulnerability may result in stealing potentially sensitive to the user information, such as cookies, or disguising the information presented on the website.
Solution:
For Hitachi Compute Systems Manager Software 7.x: Update to a fixed version.
Links:
http://www.hitachi.co.jp/Prod/comp/soft1/global/security/info/vuls/HS15-001/index.html