Vulnerabilities > Hitachi > Critical

DATE CVE VULNERABILITY TITLE RISK
2023-07-18 CVE-2022-4146 Expression Language Injection vulnerability in Hitachi Replication Manager
Expression Language Injection vulnerability in Hitachi Replication Manager on Windows, Linux, Solaris allows Code Injection.This issue affects Hitachi Replication Manager: before 8.8.5-02.
network
low complexity
hitachi CWE-917
critical
9.8
2023-04-03 CVE-2022-43939 Unspecified vulnerability in Hitachi Vantara Pentaho Business Analytics Server 9.4.0.0
Hitachi Vantara Pentaho Business Analytics Server versions before 9.4.0.1 and 9.3.0.2, including 8.3.x contain security restrictions using non-canonical URLs which can be circumvented. 
network
low complexity
hitachi
critical
9.8
2022-11-01 CVE-2022-41552 Server-Side Request Forgery (SSRF) vulnerability in Hitachi products
Server-Side Request Forgery (SSRF) vulnerability in Hitachi Infrastructure Analytics Advisor on Linux (Data Center Analytics, Analytics probe components), Hitachi Ops Center Analyzer on Linux (Hitachi Ops Center Analyzer detail view, Hitachi Ops Center Analyzer probe components) allows Server Side Request Forgery. This issue affects Hitachi Infrastructure Analytics Advisor: from 2.0.0-00 through 4.4.0-00; Hitachi Ops Center Analyzer: from 10.0.0-00 before 10.9.0-00.
network
low complexity
hitachi CWE-918
critical
9.8
2021-11-08 CVE-2021-34684 SQL Injection vulnerability in Hitachi Vantara Pentaho
Hitachi Vantara Pentaho Business Analytics through 9.1 allows an unauthenticated user to execute arbitrary SQL queries on any Pentaho data source and thus retrieve data from the related databases, as demonstrated by an api/repos/dashboards/editor URI.
network
low complexity
hitachi CWE-89
critical
9.8
2021-10-12 CVE-2021-29644 Integer Overflow or Wraparound vulnerability in Hitachi products
Hitachi JP1/IT Desktop Management 2 Agent 9 through 12 contains a remote code execution vulnerability because of an Integer Overflow.
network
low complexity
hitachi CWE-190
critical
9.8
2017-05-29 CVE-2017-9294 Unspecified vulnerability in Hitachi Device Manager
RMI vulnerability in Hitachi Device Manager before 8.5.2-01 allows remote attackers to execute internal commands without authentication via RMI ports.
network
low complexity
hitachi
critical
9.8