Записи Hitachi
214 опубликованных записей вендора hitachi.
Профиль для исследователя
- Попали в KEV
- 2 · 0,9 %
- С эксплойтом
- 2 · 0,9 %
- Pre-auth RCE
- 26
- С записью об исправлении
- 35 %
- Медиана: публикация → KEV
- 700 дн.
Повторяющиеся классы
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')21
- CWE-276 Incorrect Default Permissions10
- CWE-20 Improper Input Validation9
- CWE-532 Insertion of Sensitive Information into Log File7
- CWE-209 Generation of Error Message Containing Sensitive Information7
- CWE-200 Exposure of Sensitive Information to an Unauthorized Actor4
Классы уязвимостей, которые чаще всего встречаются у этого вендора: куда смотреть.
CWEВсе записи
214 записей| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
97Срочно | CVE-2022-43939Готовый эксплойт | Hitachi Vantara Pentaho Business Analytics Server - Use of Non-Canonical URL Paths for Authorization Decisionshitachi · vantara pentaho business analytics server · CWE-647 | Критическая9,8 | KEV | 92,3 % | 3 апр. 2023 г. |
87Срочно | CVE-2022-43769Готовый эксплойт | Hitachi Vantara Pentaho Business Analytics Server - Failure to Sanitize Special Elements into a Different Plane (Special Element Injection)hitachi · vantara pentaho business analytics server · CWE-74 | Высокая7,2 | KEV | 97,7 % | 3 апр. 2023 г. |
45В плане | CVE-2005-0356Proof of concept | Multiple TCP implementations with Protection Against Wrapped Sequence Numbers (PAWS) with the timestamps option enabled allow remote attackecisco · agent desktop | Средняя5,0 | — | 82,8 % | 31 мая 2005 г. |
45В плане | CVE-2021-31602Proof of concept | An issue was discovered in Hitachi Vantara Pentaho through 9.1 and Pentaho Business Intelligence Server through 7.x.hitachi · vantara pentaho · CWE-287 | Высокая7,5 | — | 51,7 % | 8 нояб. 2021 г. |
43В плане | CVE-2022-43938Эксплойта нет | Hitachi Vantara Pentaho Business Analytics Server - Improper Neutralization of Directives in Statically Saved Code ('Static Code Injection')hitachi · vantara pentaho business analytics server · CWE-96 | Высокая8,8 | — | 26,4 % | 3 апр. 2023 г. |
42В плане | CVE-2022-43773Эксплойта нет | Hitachi Vantara Pentaho Business Analytics Server - Incorrect Permission Assignment for Critical Resourcehitachi · vantara pentaho business analytics server · CWE-732 | Высокая8,8 | — | 22,2 % | 3 апр. 2023 г. |
42В плане | CVE-2006-6713Эксплойта нет | Buffer overflow in Hitachi Directory Server 2 P-2444-A124 before 02-11-/K on Windows, and P-1B44-A121 before 02-10-/V on HP-UX, allows remothitachi · hitachi directory server 2 | Критическая10,0 | — | 5,9 % | 22 дек. 2006 г. |
42В плане | CVE-2007-4758Эксплойта нет | Multiple buffer overflows in the image-processing APIs in Cosminexus Developer's Kit for Java in Cosminexus 4 through 7 allow remote attackehitachi · ucosminexus application server enterprise · CWE-119 | Критическая10,0 | — | 5,9 % | 8 сент. 2007 г. |
42В плане | CVE-2010-4773Эксплойта нет | Unspecified vulnerability in Hitachi EUR Form Client before 05-10 -/D 2010.11.15 and 05-10-CA (* 2) 2010.11.15; Hitachi EUR Form Service befhitachi · eur form client | Критическая10,0 | — | 5,3 % | 23 мар. 2011 г. |
41В плане | CVE-2021-34684Эксплойта нет | Hitachi Vantara Pentaho Business Analytics through 9.1 allows an unauthenticated user to execute arbitrary SQL queries on any Pentaho data shitachi · vantara pentaho · CWE-89 | Критическая9,8 | — | 5,9 % | 8 нояб. 2021 г. |
41В плане | CVE-2007-1093Эксплойта нет | Multiple unspecified vulnerabilities in JP1/Cm2/Network Node Manager (NNM) before 07-10-05, and before 08-00-02 in the 08-x series, allow rehitachi · hi ux we2 · CWE-94 | Критическая10,0 | — | 4,9 % | 26 февр. 2007 г. |
41В плане | CVE-2012-0918Эксплойта нет | Unspecified vulnerability in Hitachi COBOL2002 Net Developer, Net Server Suite, and Net Client Suite 01-00, 01-01 through 01-01-/D, 01-02 thhitachi · cobol2002 net developer | Критическая10,0 | — | 4,1 % | 24 янв. 2012 г. |
41В плане | CVE-2009-3169Эксплойта нет | Multiple unspecified vulnerabilities in Hitachi JP1/File Transmission Server/FTP before 09-00 allow remote attackers to execute arbitrary cohitachi · jp1 file transmission server | Критическая10,0 | — | 3,9 % | 11 сент. 2009 г. |
41В плане | CVE-2012-4274Эксплойта нет | Unspecified vulnerability in Hitachi Cobol GUI Option 06-00, 06-01 through 06-01-/A, 07-00, 07-01 before 07-01-/B, and 08-00 before 08-00-/Bhitachi · cobol gui option | Критическая10,0 | — | 3,5 % | 13 авг. 2012 г. |
41В плане | CVE-2007-3794Эксплойта нет | Buffer overflow in Hitachi Cosminexus V4 through V7, Processing Kit for XML before 20070511, Developer's Kit for Java before 20070312, and thitachi · cosminexus application server | Критическая10,0 | — | 2,2 % | 15 июл. 2007 г. |
41В плане | CVE-2004-2421Эксплойта нет | Unknown vulnerability in Hitachi Job Management Partner (JP1) JP1/File Transmission Server/FTP 6 and 7, when running on HP-UX in trusted modhitachi · jp1 p-1b41-9461 | Критическая10,0 | — | 1,9 % | 31 дек. 2004 г. |
40В плане | CVE-2021-29644Эксплойта нет | Hitachi JP1/IT Desktop Management 2 Agent 9 through 12 contains a remote code execution vulnerability because of an Integer Overflow.hitachi · it operations director · CWE-190 | Критическая9,8 | — | 2,5 % | 12 окт. 2021 г. |
40В плане | CVE-2017-9294Эксплойта нет | RMI vulnerability in Hitachi Device Manager before 8.5.2-01 allows remote attackers to execute internal commands without authentication via hitachi · device manager | Критическая9,8 | — | 2,4 % | 29 мая 2017 г. |
39Наблюдать | CVE-2025-9661Эксплойта нет | OS command injection vulneravility in the management gui (maintenance utility) of Hitachi Virtual Storage Platform One Block 23/24/26/28hitachi · virtual storage one block · CWE-78 | Критическая9,8 | — | 0,9 % | 7 мая 2026 г. |
39Наблюдать | CVE-2022-41552Эксплойта нет | Server-Side Request Forgery Vulnerability in Hitachi Infrastructure Analytics Advisor, Hitachi Ops Center Analyzerhitachi · infrastructure analytics advisor · CWE-918 | Критическая9,8 | — | 0,7 % | 31 окт. 2022 г. |
39Наблюдать | CVE-2025-65115Эксплойта нет | Remote Code Execution Vulnerability in JP1/IT Desktop Management 2 and JP1/NETM/DMhitachi · job management partner 1\/it desktop management-manager · CWE-73 | Критическая9,8 | — | 0,6 % | 7 апр. 2026 г. |
39Наблюдать | CVE-2025-1978Эксплойта нет | Remote Code Execution Vulnerability in Hitachi Storage Navigator and the maintenance consolehitachi · virtual storage one block · CWE-94 | Критическая9,8 | — | 0,5 % | 7 мая 2026 г. |
39Наблюдать | CVE-2022-4146Эксплойта нет | EL Injection Vulnerability in Hitachi Replication Managerhitachi · replication manager · CWE-917 | Критическая9,8 | — | 0,5 % | 17 июл. 2023 г. |
39Наблюдать | CVE-2024-0715Эксплойта нет | EL Injection Vulnerability in Hitachi Global Link Managerhitachi · global link manager · CWE-917 | Критическая9,8 | — | 0,5 % | 19 февр. 2024 г. |
39Наблюдать | CVE-2024-5828Эксплойта нет | EL Injection Vulnerability in Hitachi Tuning Managerhitachi · tuning manager · CWE-917 | Критическая9,8 | — | 0,4 % | 5 авг. 2024 г. |
- CVE-2022-4393997Срочно
Hitachi Vantara Pentaho Business Analytics Server - Use of Non-Canonical URL Paths for Authorization Decisions
КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 92 %hitachi · vantara pentaho business analytics server3 апр. 2023 г.
- CVE-2022-4376987Срочно
Hitachi Vantara Pentaho Business Analytics Server - Failure to Sanitize Special Elements into a Different Plane (Special Element Injection)
ВысокаяCVSS 7,2KEVГотовый эксплойтEPSS 98 %hitachi · vantara pentaho business analytics server3 апр. 2023 г.
- CVE-2005-035645В плане
Multiple TCP implementations with Protection Against Wrapped Sequence Numbers (PAWS) with the timestamps option enabled allow remote attacke
СредняяCVSS 5,0Proof of conceptEPSS 83 %cisco · agent desktop31 мая 2005 г.
- CVE-2021-3160245В плане
An issue was discovered in Hitachi Vantara Pentaho through 9.1 and Pentaho Business Intelligence Server through 7.x.
ВысокаяCVSS 7,5Proof of conceptEPSS 52 %hitachi · vantara pentaho8 нояб. 2021 г.
- CVE-2022-4393843В плане
Hitachi Vantara Pentaho Business Analytics Server - Improper Neutralization of Directives in Statically Saved Code ('Static Code Injection')
ВысокаяCVSS 8,8Эксплойта нетEPSS 26 %hitachi · vantara pentaho business analytics server3 апр. 2023 г.
- CVE-2022-4377342В плане
Hitachi Vantara Pentaho Business Analytics Server - Incorrect Permission Assignment for Critical Resource
ВысокаяCVSS 8,8Эксплойта нетEPSS 22 %hitachi · vantara pentaho business analytics server3 апр. 2023 г.
- CVE-2006-671342В плане
Buffer overflow in Hitachi Directory Server 2 P-2444-A124 before 02-11-/K on Windows, and P-1B44-A121 before 02-10-/V on HP-UX, allows remot
КритическаяCVSS 10,0Эксплойта нетEPSS 6 %hitachi · hitachi directory server 222 дек. 2006 г.
- CVE-2007-475842В плане
Multiple buffer overflows in the image-processing APIs in Cosminexus Developer's Kit for Java in Cosminexus 4 through 7 allow remote attacke
КритическаяCVSS 10,0Эксплойта нетEPSS 6 %hitachi · ucosminexus application server enterprise8 сент. 2007 г.
- CVE-2010-477342В плане
Unspecified vulnerability in Hitachi EUR Form Client before 05-10 -/D 2010.11.15 and 05-10-CA (* 2) 2010.11.15; Hitachi EUR Form Service bef
КритическаяCVSS 10,0Эксплойта нетEPSS 5 %hitachi · eur form client23 мар. 2011 г.
- CVE-2021-3468441В плане
Hitachi Vantara Pentaho Business Analytics through 9.1 allows an unauthenticated user to execute arbitrary SQL queries on any Pentaho data s
КритическаяCVSS 9,8Эксплойта нетEPSS 6 %hitachi · vantara pentaho8 нояб. 2021 г.
- CVE-2007-109341В плане
Multiple unspecified vulnerabilities in JP1/Cm2/Network Node Manager (NNM) before 07-10-05, and before 08-00-02 in the 08-x series, allow re
КритическаяCVSS 10,0Эксплойта нетEPSS 5 %hitachi · hi ux we226 февр. 2007 г.
- CVE-2012-091841В плане
Unspecified vulnerability in Hitachi COBOL2002 Net Developer, Net Server Suite, and Net Client Suite 01-00, 01-01 through 01-01-/D, 01-02 th
КритическаяCVSS 10,0Эксплойта нетEPSS 4 %hitachi · cobol2002 net developer24 янв. 2012 г.
- CVE-2009-316941В плане
Multiple unspecified vulnerabilities in Hitachi JP1/File Transmission Server/FTP before 09-00 allow remote attackers to execute arbitrary co
КритическаяCVSS 10,0Эксплойта нетEPSS 4 %hitachi · jp1 file transmission server11 сент. 2009 г.
- CVE-2012-427441В плане
Unspecified vulnerability in Hitachi Cobol GUI Option 06-00, 06-01 through 06-01-/A, 07-00, 07-01 before 07-01-/B, and 08-00 before 08-00-/B
КритическаяCVSS 10,0Эксплойта нетEPSS 3 %hitachi · cobol gui option13 авг. 2012 г.
- CVE-2007-379441В плане
Buffer overflow in Hitachi Cosminexus V4 through V7, Processing Kit for XML before 20070511, Developer's Kit for Java before 20070312, and t
КритическаяCVSS 10,0Эксплойта нетEPSS 2 %hitachi · cosminexus application server15 июл. 2007 г.
- CVE-2004-242141В плане
Unknown vulnerability in Hitachi Job Management Partner (JP1) JP1/File Transmission Server/FTP 6 and 7, when running on HP-UX in trusted mod
КритическаяCVSS 10,0Эксплойта нетEPSS 2 %hitachi · jp1 p-1b41-946131 дек. 2004 г.
- CVE-2021-2964440В плане
Hitachi JP1/IT Desktop Management 2 Agent 9 through 12 contains a remote code execution vulnerability because of an Integer Overflow.
КритическаяCVSS 9,8Эксплойта нетEPSS 3 %hitachi · it operations director12 окт. 2021 г.
- CVE-2017-929440В плане
RMI vulnerability in Hitachi Device Manager before 8.5.2-01 allows remote attackers to execute internal commands without authentication via
КритическаяCVSS 9,8Эксплойта нетEPSS 2 %hitachi · device manager29 мая 2017 г.
- CVE-2025-966139Наблюдать
OS command injection vulneravility in the management gui (maintenance utility) of Hitachi Virtual Storage Platform One Block 23/24/26/28
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %hitachi · virtual storage one block7 мая 2026 г.
- CVE-2022-4155239Наблюдать
Server-Side Request Forgery Vulnerability in Hitachi Infrastructure Analytics Advisor, Hitachi Ops Center Analyzer
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %hitachi · infrastructure analytics advisor31 окт. 2022 г.
- CVE-2025-6511539Наблюдать
Remote Code Execution Vulnerability in JP1/IT Desktop Management 2 and JP1/NETM/DM
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %hitachi · job management partner 1\/it desktop management-manager7 апр. 2026 г.
- CVE-2025-197839Наблюдать
Remote Code Execution Vulnerability in Hitachi Storage Navigator and the maintenance console
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %hitachi · virtual storage one block7 мая 2026 г.
- CVE-2022-414639Наблюдать
EL Injection Vulnerability in Hitachi Replication Manager
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %hitachi · replication manager17 июл. 2023 г.
- CVE-2024-071539Наблюдать
EL Injection Vulnerability in Hitachi Global Link Manager
КритическаяCVSS 9,8Эксплойта нетEPSS 0 %hitachi · global link manager19 февр. 2024 г.
- CVE-2024-582839Наблюдать
EL Injection Vulnerability in Hitachi Tuning Manager
КритическаяCVSS 9,8Эксплойта нетEPSS 0 %hitachi · tuning manager5 авг. 2024 г.