[Forgot Password]
Login  Register Subscribe

30430

 
 

423868

 
 

247621

 
 

909

 
 

194512

 
 

282

Paid content will be excluded from the download.


Download | Alert*
CVE
view JSON

CVE-2014-4188Date: (C)2014-06-17   (M)2023-12-22


Cross-site request forgery (CSRF) vulnerability in Hitachi Tuning Manager before 7.6.1-06 and 8.x before 8.0.0-04 and JP1/Performance Management - Manager Web Option 07-00 through 07-54 allows remote attackers to hijack the authentication of unspecified victims via unknown vectors.

CVSS Score and Metrics +CVSS Score and Metrics -

CVSS V2 Severity:
CVSS Score : 6.8
Exploit Score: 8.6
Impact Score: 6.4
 
CVSS V2 Metrics:
Access Vector: NETWORK
Access Complexity: MEDIUM
Authentication: NONE
Confidentiality: PARTIAL
Integrity: PARTIAL
Availability: PARTIAL
  
Reference:
SECUNIA-58528
SECUNIA-58899
BID-68015
http://www.hitachi.co.jp/Prod/comp/soft1/global/security/info/vuls/HS14-013/index.html

CPE    9
cpe:/a:hitachi:tuning_manager:7.6.1:05:~~~solaris~~
cpe:/a:hitachi:tuning_manager:7.1.0::~~~linux_kernel~~
cpe:/a:hitachi:tuning_manager:8.0.0::~~~windows~~
cpe:/a:hitachi:tuning_manager:8.0.0::~~~linux_kernel~~
...
CWE    1
CWE-352

© SecPod Technologies