Vulnerabilities > Hitachi

DATE CVE VULNERABILITY TITLE RISK
2023-07-18 CVE-2023-34142 Cleartext Transmission of Sensitive Information vulnerability in Hitachi Device Manager
Cleartext Transmission of Sensitive Information vulnerability in Hitachi Device Manager on Windows, Linux (Device Manager Server, Device Manager Agent, Host Data Collector components) allows Interception.This issue affects Hitachi Device Manager: before 8.8.5-02.
network
low complexity
hitachi CWE-319
7.5
2023-07-18 CVE-2023-34143 Improper Certificate Validation vulnerability in Hitachi Device Manager
Improper Validation of Certificate with Host Mismatch vulnerability in Hitachi Device Manager on Windows, Linux (Device Manager Server, Device Manager Agent, Host Data Collector components) allows Man in the Middle Attack.This issue affects Hitachi Device Manager: before 8.8.5-02.
network
high complexity
hitachi CWE-295
8.1
2023-05-24 CVE-2022-4815 Deserialization of Untrusted Data vulnerability in Hitachi products
Hitachi Vantara Pentaho Business Analytics Server versions before 9.4.0.1 and 9.3.0.3, including 8.3.x deserialize untrusted JSON data without constraining the parser to approved classes and methods. 
network
low complexity
hitachi CWE-502
8.8
2023-05-24 CVE-2023-1158 Incorrect Authorization vulnerability in Hitachi products
Hitachi Vantara Pentaho Business Analytics Server versions before 9.4.0.1 and 9.3.0.3, including 8.3.x expose dashboard prompts to users who are not part of the authorization list. 
network
low complexity
hitachi CWE-863
4.3
2023-05-23 CVE-2023-30469 Cross-site Scripting vulnerability in Hitachi OPS Center Analyzer 10.9.100
Cross-site Scripting vulnerability in Hitachi Ops Center Analyzer (Hitachi Ops Center Analyzer detail view component) allows Reflected XSS.This issue affects Hitachi Ops Center Analyzer: from 10.9.1-00 before 10.9.2-00.
network
low complexity
hitachi CWE-79
6.1
2023-04-03 CVE-2022-3960 Code Injection vulnerability in Hitachi Vantara Pentaho Business Analytics Server 9.4.0.0
Hitachi Vantara Pentaho Business Analytics Server prior to versions 9.4.0.1 and 9.3.0.2, including 8.3.x cannot allow a system administrator to disable scripting capabilities of the Community Dashboard Editor (CDE) plugin. 
network
low complexity
hitachi CWE-94
6.3
2023-04-03 CVE-2022-43771 Path Traversal vulnerability in Hitachi Vantara Pentaho Business Analytics Server
Hitachi Vantara Pentaho Business Analytics Server versions before 9.4.0.0 and 9.3.0.1, including 8.3.x, using the Pentaho Data Access plugin exposes a service endpoint for CSV import which allows a user supplied path to access resources that are out of bounds.
network
low complexity
hitachi CWE-22
6.5
2023-04-03 CVE-2022-43772 Information Exposure Through Log Files vulnerability in Hitachi Vantara Pentaho Business Analytics Server
Hitachi Vantara Pentaho Business Analytics Server versions before 9.4.0.0 and 9.3.0.1, including 8.3.x with the Big Data Plugin expose the username and password of clusters in clear text into system logs. 
network
low complexity
hitachi CWE-532
6.5
2023-04-03 CVE-2022-43938 Code Injection vulnerability in Hitachi Vantara Pentaho Business Analytics Server 9.4.0.0
Hitachi Vantara Pentaho Business Analytics Server prior to versions 9.4.0.1 and 9.3.0.2, including 8.3.x cannot allow a system administrator to disable scripting capabilities of Pentaho Reports (*.prpt) through the JVM script manager. 
network
low complexity
hitachi CWE-94
8.8
2023-04-03 CVE-2022-43940 Incorrect Authorization vulnerability in Hitachi Vantara Pentaho Business Analytics Server 9.4.0.0
Hitachi Vantara Pentaho Business Analytics Server versions before 9.4.0.1 and 9.3.0.2, including 8.3.x do not correctly perform an authorization check in the data source management service. 
network
low complexity
hitachi CWE-863
8.8