Hitachi Command Suite Products Unspecified Cross Site Scripting Vulnerability
BID:52099
Info
Hitachi Command Suite Products Unspecified Cross Site Scripting Vulnerability
| Bugtraq ID: | 52099 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Feb 21 2012 12:00AM |
| Updated: | Feb 21 2012 12:00AM |
| Credit: | Reported by the vendor |
| Vulnerable: |
Hitachi Tiered Storage Manager Software 7.1.0-00 (Windows) Hitachi Tiered Storage Manager Software 7.1.0-00 (Solaris(SP Hitachi Tiered Storage Manager Software 7.1.0-00 (Linux(SLES Hitachi Tiered Storage Manager Software 7.1.0-00 (Linux(RHEL Hitachi Tiered Storage Manager Software 7.0.1-02 (Windows) Hitachi Tiered Storage Manager Software 7.0.1-02 (linux(SLES Hitachi Tiered Storage Manager Software 7.0.1-02 (linux(RHEL Hitachi Tiered Storage Manager Software 7.0.0-00 (Windows) Hitachi Tiered Storage Manager Software 7.0.0-00 (Solaris(SP Hitachi Tiered Storage Manager Software 7.0.0-00 (linux(SLES Hitachi Tiered Storage Manager Software 7.0.0-00 (linux(RHEL Hitachi Device Manager Software 7.1.0-00 (Windows) Hitachi Device Manager Software 7.1.0-00 (Solaris(SP Hitachi Device Manager Software 7.1.0-00 (Linux(SLES Hitachi Device Manager Software 7.1.0-00 (Linux(RHEL Hitachi Device Manager Software 7.0.1-02 (Windows) Hitachi Device Manager Software 7.0.1-02 (linux(SLES Hitachi Device Manager Software 7.0.1-02 (linux(RHEL Hitachi Device Manager Software 7.0.0-00 (Windows) Hitachi Device Manager Software 7.0.0-00 (Solaris(SP Hitachi Device Manager Software 7.0.0-00 (linux(SLES Hitachi Device Manager Software 7.0.0-00 (linux(RHEL |
| Not Vulnerable: |
Hitachi Tiered Storage Manager Software 7.2.1-00 Hitachi Device Manager Software 7.2.1-00 |
Discussion
Hitachi Command Suite Products Unspecified Cross Site Scripting Vulnerability
Multiple Hitachi Command Suite Products, including Device Manager Software and Tiered Storage Manager Software, are prone to an unspecified cross-site scripting vulnerability because they fail to properly sanitize user-supplied input.
An attacker may leverage this issue to execute arbitrary script code in the browser of an unsuspecting user in the context of the affected site. This may let the attacker steal cookie-based authentication credentials and launch other attacks.
Multiple Hitachi Command Suite Products, including Device Manager Software and Tiered Storage Manager Software, are prone to an unspecified cross-site scripting vulnerability because they fail to properly sanitize user-supplied input.
An attacker may leverage this issue to execute arbitrary script code in the browser of an unsuspecting user in the context of the affected site. This may let the attacker steal cookie-based authentication credentials and launch other attacks.
Exploit / POC
Hitachi Command Suite Products Unspecified Cross Site Scripting Vulnerability
Attackers can exploit this issue by enticing an unsuspecting user to follow a malicious URI.
Attackers can exploit this issue by enticing an unsuspecting user to follow a malicious URI.
Solution / Fix
Hitachi Command Suite Products Unspecified Cross Site Scripting Vulnerability
Solution:
Vendor updates are available. Please see the references for more details.
Solution:
Vendor updates are available. Please see the references for more details.
References
Hitachi Command Suite Products Unspecified Cross Site Scripting Vulnerability
References:
References:
- Hitachi Homepage (Hitachi)
- Cross-site Scripting Vulnerability in Hitachi Command Suite Products (Hitachi)