Hitachi JP1/Performance Management Web Console Unspecified Cross-Site Scripting Vulnerability
BID:48679
Info
Hitachi JP1/Performance Management Web Console Unspecified Cross-Site Scripting Vulnerability
| Bugtraq ID: | 48679 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Jul 14 2011 12:00AM |
| Updated: | Jul 14 2011 12:00AM |
| Credit: | The vendor disclosed this issue. |
| Vulnerable: |
Hitachi JP1/Performance Management - Web Console 09-10-03 Hitachi JP1/Performance Management - Web Console 09-10 Hitachi JP1/Performance Management - Web Console 09-00-08 Hitachi JP1/Performance Management - Web Console 09-00-07 Hitachi JP1/Performance Management - Web Console 09-00 Hitachi JP1/Performance Management - Web Console 08-50-09 Hitachi JP1/Performance Management - Web Console 08-50 Hitachi JP1/Performance Management - Web Console 08-11-07 Hitachi JP1/Performance Management - Web Console 08-11 Hitachi JP1/Performance Management - Web Console 08-10-07 Hitachi JP1/Performance Management - Web Console 08-10 Hitachi JP1/Performance Management - Web Console 08-00-11 Hitachi JP1/Performance Management - Web Console 08-00 Hitachi JP1/Performance Management - Web Console 0 |
| Not Vulnerable: |
Hitachi JP1/Performance Management - Web Console 2011.02.10 08-00-12 Hitachi JP1/Performance Management - Web Console 2011.02.09 08-10-08 Hitachi JP1/Performance Management - Web Console 2011.02.02 08-11-08 Hitachi JP1/Performance Management - Web Console 2011.02.01 08-50-10 Hitachi JP1/Performance Management - Web Console 2011.01.27 08-50-10 Hitachi JP1/Performance Management - Web Console 2011.01.14 09-00-09 Hitachi JP1/Performance Management - Web Console 2010.12.24 09-10-04 |
Discussion
Hitachi JP1/Performance Management Web Console Unspecified Cross-Site Scripting Vulnerability
Hitachi JP1/Performance Management - Web Console is prone to a cross-site scripting vulnerability because it fails to properly sanitize user-supplied input.
An attacker may leverage this issue to execute arbitrary script code in the browser of an unsuspecting user in the context of the affected site. This may help the attacker steal cookie-based authentication credentials and launch other attacks.
Hitachi JP1/Performance Management - Web Console is prone to a cross-site scripting vulnerability because it fails to properly sanitize user-supplied input.
An attacker may leverage this issue to execute arbitrary script code in the browser of an unsuspecting user in the context of the affected site. This may help the attacker steal cookie-based authentication credentials and launch other attacks.
Exploit / POC
Hitachi JP1/Performance Management Web Console Unspecified Cross-Site Scripting Vulnerability
An attacker can exploit this issue by enticing an unsuspecting user to follow a malicious URI.
An attacker can exploit this issue by enticing an unsuspecting user to follow a malicious URI.
Solution / Fix
Hitachi JP1/Performance Management Web Console Unspecified Cross-Site Scripting Vulnerability
Solution:
The vendor released updates to address this issue. Please see the referenced advisory for more information.
Solution:
The vendor released updates to address this issue. Please see the referenced advisory for more information.
References
Hitachi JP1/Performance Management Web Console Unspecified Cross-Site Scripting Vulnerability
References:
References:
- Hitachi Homepage (Hitachi)
- HS11-014 JP1/Performance Management - Web Console (Hitachi)