High severity7.2NVD Advisory· Published Nov 17, 2021· Updated Jun 17, 2026
CVE-2021-35528
CVE-2021-35528
Description
Improper Access Control vulnerability in the application authentication and authorization of Hitachi Energy Retail Operations, Counterparty Settlement and Billing (CSB) allows an attacker to execute a modified signed Java Applet JAR file. A successful exploitation may lead to data extraction or modification of data inside the application. This issue affects: Hitachi Energy Retail Operations 5.7.3 and prior versions. Hitachi Energy Counterparty Settlement and Billing (CSB) 5.7.3 prior versions.
Affected products
6- Hitachi Energy/Retail Operationsv5Range: 5.7.3
- cpe:2.3:a:hitachienergy:counterparty_settlements_and_billing:*:*:*:*:*:*:*:*Range: <=5.7.3
- cpe:2.3:a:hitachienergy:retail_operations:*:*:*:*:*:*:*:*Range: <=5.7.3
<=5.7.3+ 1 more
- (no CPE)range: <=5.7.3
- (no CPE)range: 5.7.3
- Range: <=5.7.3
Patches
Vulnerability mechanics
References
2- search.abb.com/library/Download.aspxnvdVendor Advisory
- search.abb.com/library/Download.aspxnvdVendor Advisory
News mentions
0No linked articles in our index yet.