VYPR

Vendor CVEs

Hitachi

All CVEs

357 total · sorted by risk
  • CVE-2025-1531MedMay 16, 2025
    risk 0.42cvss 6.5epss 0.00

    Authentication credentials leakage vulnerability in Hitachi Ops Center Analyzer viewpoint.This issue affects Hitachi Ops Center Analyzer viewpoint: from 10.0.0-00 before 11.0.4-00.

  • CVE-2025-1245MedMay 16, 2025
    risk 0.42cvss 6.5epss 0.00

    Bypass Connection Restriction vulnerability in Hitachi Infrastructure Analytics Advisor (Data Center Analytics component), Hitachi Ops Center Analyzer  (Hitachi Ops Center Analyzer detail view component).This issue affects Hitachi Infrastructure Analytics Advisor:; Hitachi Ops…

  • CVE-2025-27631MedMar 25, 2025
    risk 0.42cvss 6.5epss 0.00

    The TRMTracker web application is vulnerable to LDAP injection attack potentially allowing an attacker to inject code into a query and execute remote commands that can read and update data on the website.

  • CVE-2024-12169MedMar 25, 2025
    risk 0.42cvss 6.5epss 0.00

    A vulnerability exists in RTU500 IEC 60870-5-104 controlled station functionality and IEC 61850 functionality, that allows an attacker performing a specific attack sequence to restart the affected CMU. This vulnerability only applies, if secure communication using IEC 62351-3…

  • CVE-2024-6697MedFeb 20, 2025
    risk 0.42cvss 6.5epss 0.00

    The product does not handle or incorrectly handles when it has insufficient privileges to access resources or functionality as specified by their permissions. This may cause it to follow unexpected code paths that may leave the product in an invalid state. (CWE-280)   …

  • CVE-2024-37363MedFeb 20, 2025
    risk 0.42cvss 6.5epss 0.00

    The product does not perform an authorization check when an actor attempts to access a resource or perform an action. (CWE-862)  Hitachi Vantara Pentaho Business Analytics Server versions before 10.2.0.0 and 9.3.0.8, including 8.3.x, do not correctly perform an…

  • CVE-2024-28022MedJun 11, 2024
    risk 0.42cvss 6.5epss 0.00

    A vulnerability exists in the UNEM server / APIGateway that if exploited allows a malicious user to perform an arbitrary number of authentication attempts using different passwords, and eventually gain access to other components in the same security realm using the targeted…

  • CVE-2023-3335MedOct 3, 2023
    risk 0.42cvss 6.5epss 0.00

    Insertion of Sensitive Information into Log File vulnerability in Hitachi Ops Center Administrator on Linux allows local users  to gain sensitive information.This issue affects Hitachi Ops Center Administrator: before 10.9.3-00.

  • CVE-2022-3695MedApr 11, 2023
    risk 0.42cvss 6.5epss 0.00

    Hitachi Vantara Pentaho Business Analytics Server prior to versions 9.3.0.0, 9.2.0.4 and 8.3.0.27 allow a malicious URL to inject content into a dashboard when the CDE plugin is present.   

  • CVE-2022-41553MedNov 1, 2022
    risk 0.42cvss 6.5epss 0.00

    Insertion of Sensitive Information into Temporary File vulnerability in Hitachi Infrastructure Analytics Advisor on Linux (Analytics probe component), Hitachi Ops Center Analyzer on Linux (Hitachi Ops Center Analyzer probe component) allows local users to gain sensitive…

  • CVE-2020-24665MedJan 29, 2021
    risk 0.42cvss 6.5epss 0.01

    The Dashboard Editor in Hitachi Vantara Pentaho through 7.x - 8.x contains an XML Entity Expansion injection vulnerability, which allows an authenticated remote users to trigger a denial of service (DoS) condition. Specifically, the vulnerability lies in the 'dashboardXml'…

  • CVE-2018-21033MedFeb 14, 2020
    risk 0.42cvss 6.5epss 0.01

    A vulnerability in Hitachi Command Suite prior to 8.6.2-00, Hitachi Automation Director prior to 8.6.2-00 and Hitachi Infrastructure Analytics Advisor prior to 4.2.0-00 allow authenticated remote users to load an arbitrary Cascading Style Sheets (CSS) token sequence. Hitachi…

  • CVE-2017-9295MedMay 29, 2017
    risk 0.42cvss 6.5epss 0.01

    XXE vulnerability in Hitachi Device Manager before 8.5.2-01 and Hitachi Replication Manager before 8.5.2-00 allows authenticated remote users to read arbitrary files.

  • CVE-2026-2254MedMay 27, 2026
    risk 0.41cvss 6.3epss 0.00

    Hitachi Vantara Pentaho Data Integration & Analytics versions before 10.2.0.6 and 11.0.0.0, including 9.3.x and 8.3.x, does not apply ACLs on certain API endpoints related to platform mail notfications.

  • CVE-2024-37362MedFeb 20, 2025
    risk 0.41cvss 6.3epss 0.00

    The product transmits or stores authentication credentials, but it uses an insecure method that is susceptible to unauthorized interception and/or retrieval. (CWE-522)   Hitachi Vantara Pentaho Data Integration & Analytics versions before 10.2.0.0 and 9.3.0.8, including…

  • CVE-2022-3960MedApr 3, 2023
    risk 0.41cvss 6.3epss 0.00

    Hitachi Vantara Pentaho Business Analytics Server prior to versions 9.4.0.1 and 9.3.0.2, including 8.3.x cannot allow a system administrator to disable scripting capabilities of the Community Dashboard Editor (CDE) plugin. 

  • CVE-2025-39201MedJun 24, 2025
    risk 0.40cvss 6.1epss 0.00

    A vulnerability exists in MicroSCADA X SYS600 product. If exploited this could allow a local unauthenticated attacker to tamper a system file, making denial of Notify service.

  • CVE-2025-0758MedApr 16, 2025
    risk 0.40cvss 6.1epss 0.00

    Overview  The product specifies permissions for a security-critical resource in a way that allows that resource to be read or modified by unintended actors. (CWE-732)  Description  Hitachi Vantara Pentaho Business Analytics Server prior to versions 10.2.0.2,…

  • CVE-2025-27633MedMar 25, 2025
    risk 0.40cvss 6.1epss 0.00

    The TRMTracker web application is vulnerable to reflected Cross-site scripting attack. The application allows client-side code injection that might be used to compromise the confidentiality and integrity of the system.

  • CVE-2025-27632MedMar 25, 2025
    risk 0.40cvss 6.1epss 0.00

    A Host Header Injection vulnerability in TRMTracker application may allow an attacker by modifying the host header value in an HTTP request to leverage multiple attack vectors, including defacing the site content through web-cache poisoning.

  • CVE-2021-20741MedJun 22, 2021
    risk 0.40cvss 6.1epss 0.01

    Cross-site scripting vulnerability in Hitachi Application Server Help (Hitachi Application Server V10 Manual (Windows) version 10-11-01 and earlier and Hitachi Application Server V10 Manual (UNIX) version 10-11-01 and earlier) allows a remote attacker to inject an arbitrary…

  • CVE-2017-9297MedMay 29, 2017
    risk 0.40cvss 6.1epss 0.01

    Open Redirect vulnerability in Hitachi Device Manager before 8.5.2-01 allows remote attackers to redirect users to arbitrary web sites.

  • CVE-2017-9296MedMay 29, 2017
    risk 0.40cvss 6.1epss 0.01

    Open Redirect vulnerability in Hitachi Device Manager before 8.5.2-01 and Hitachi Tuning Manager before 8.5.2-00 allows remote attackers to redirect authenticated users to arbitrary web sites.

  • CVE-2023-5767MedDec 4, 2023
    risk 0.39cvss 6.0epss 0.00

    A vulnerability exists in the webserver that affects the RTU500 series product versions listed below. A malicious actor could perform cross-site scripting on the webserver due to an RDT language file being improperly sanitized.

  • CVE-2021-35530MedJun 7, 2022
    risk 0.39cvss 6.0epss 0.00

    A vulnerability in the application authentication and authorization mechanism in Hitachi Energy's TXpert Hub CoreTec 4, that depends on a token validation of the session identifier, allows an unauthorized modified message to be executed in the server enabling an unauthorized…

  • CVE-2021-31602MedNov 8, 2021
    risk 0.39cvss 5.3epss 0.52

    An issue was discovered in Hitachi Vantara Pentaho through 9.1 and Pentaho Business Intelligence Server through 7.x. The Security Model has different layers of Access Control. One of these layers is the applicationContext security, which is defined in the…

  • CVE-2026-17539MedSep 3, 2026
    risk 0.38cvss 5.9epss 0.00

    RTU500 has a vulnerability, where high-load scenarios, such as sending GI requests at short intervals, may cause a NULL pointer dereference in the last entry of the enhanced message queue. This can cause a BCI_IEC104 fatal write error, resulting in connection interruption and…

  • CVE-2023-6711MedDec 19, 2023
    risk 0.38cvss 5.9epss 0.01

    Vulnerability exists in SCI IEC 60870-5-104 and HCI IEC 60870-5-104 that affects the RTU500 series product versions listed below. Specially crafted messages sent to the mentioned components are not validated properly and can result in buffer overflow and as final consequence to…

  • CVE-2023-5768MedDec 4, 2023
    risk 0.38cvss 5.9epss 0.00

    A vulnerability exists in the HCI IEC 60870-5-104 that affects the RTU500 series product versions listed below. Incomplete or wrong received APDU frame layout may cause blocking on link layer. Error reason was an endless blocking when reading incoming frames on link layer …

  • CVE-2022-3353MedFeb 21, 2023
    risk 0.38cvss 5.9epss 0.01

    A vulnerability exists in the IEC 61850 communication stack that affects multiple Hitachi Energy products.  An attacker could exploit the vulnerability by using a specially crafted message sequence, to force the IEC 61850 MMS-server communication stack, to stop accepting…

  • CVE-2022-4041MedJan 31, 2023
    risk 0.38cvss 5.9epss 0.01

    Incorrect Privilege Assignment vulnerability in Hitachi Storage Plug-in for VMware vCenter allows remote authenticated users to cause privilege escalation. This issue affects Hitachi Storage Plug-in for VMware vCenter: from 04.8.0 before 04.9.1.

  • CVE-2022-2155MedJan 12, 2023
    risk 0.37cvss 5.7epss 0.00

    A vulnerability exists in the affected versions of Lumada APM’s User Asset Group feature due to a flaw in access control mechanism implementation on the “Limited Engineer” role, granting it access to the embedded Power BI reports feature. An attacker that manages to…

  • CVE-2025-65116MedApr 7, 2026
    risk 0.36cvss 5.5epss 0.00

    Buffer Overflow Vulnerability in JP1/IT Desktop Management 2 - Manager on Windows, JP1/IT Desktop Management 2 - Operations Director on Windows, Job Management Partner 1/IT Desktop Management 2 - Manager on Windows, JP1/IT Desktop Management - Manager on Windows, Job Management…

  • CVE-2025-2300MedApr 22, 2025
    risk 0.36cvss 5.5epss 0.00

    Hitachi Ops Center Common Services within Hitachi Ops Center OVA contains an information exposure vulnerability. This issue affects Hitachi Ops Center Common Services: from 11.0.3-00 before 11.0.4-00.

  • CVE-2023-6814MedMar 12, 2024
    risk 0.36cvss 5.6epss 0.00

    Insertion of Sensitive Information into Log File vulnerability in Hitachi Cosminexus Component Container allows local users to gain sensitive information.This issue affects Cosminexus Component Container: from 11-30 before 11-30-05, from 11-20 before 11-20-07, from 11-10 before…

  • CVE-2023-34143MedJul 18, 2023
    risk 0.36cvss 5.6epss 0.00

    Improper Validation of Certificate with Host Mismatch vulnerability in Hitachi Device Manager on Windows, Linux (Device Manager Server, Device Manager Agent, Host Data Collector components) allows Man in the Middle Attack.This issue affects Hitachi Device Manager: before…

  • CVE-2024-8201MedMay 16, 2025
    risk 0.35cvss 5.4epss 0.00

    Cross-Site WebSocket Hijacking vulnerability in Hitachi Ops Center Analyzer (RAID Agent component).This issue affects Hitachi Ops Center Analyzer: from 10.8.0-00 before 11.0.4-00; Hitachi Ops Center Analyzer: from 10.9.0-00 before 11.0.4-00.

  • CVE-2023-5769MedDec 14, 2023
    risk 0.35cvss 5.4epss 0.00

    A vulnerability exists in the webserver that affects the RTU500 series product versions listed below. A malicious actor could perform cross-site scripting on the webserver due to user input being improperly sanitized.

  • CVE-2022-43770MedApr 11, 2023
    risk 0.35cvss 5.4epss 0.00

    Hitachi Vantara Pentaho Business Analytics Server versions before 9.3.0.0, 9.2.0.4 and 8.3.0.27 does not correctly perform an authorization check in the dashboard editor plugin API.   

  • CVE-2022-4771MedApr 3, 2023
    risk 0.35cvss 5.4epss 0.00

    Hitachi Vantara Pentaho Business Analytics Server prior to versions 9.4.0.1 and 9.3.0.2, including 8.3.x allow a malicious URL to inject content into the Pentaho User Console through session variables. 

  • CVE-2022-2637MedOct 6, 2022
    risk 0.35cvss 5.4epss 0.01

    Incorrect Privilege Assignment vulnerability in Hitachi Hitachi Storage Plug-in for VMware vCenter allows remote authenticated users to cause privilege escalation.This issue affects Hitachi Storage Plug-in for VMware vCenter: from 04.8.0 before 04.9.0.

  • CVE-2022-29492MedSep 14, 2022
    risk 0.35cvss 5.3epss 0.01

    Improper Input Validation vulnerability in the handling of a malformed IEC 104 TCP packet in the Hitachi Energy MicroSCADA X SYS600, MicroSCADA Pro SYS600. Upon receiving a malformed IEC 104 TCP packet, the malformed packet is dropped, however the TCP connection is left open.…

  • CVE-2020-24670MedJan 29, 2021
    risk 0.35cvss 5.4epss 0.01

    The Dashboard Editor in Hitachi Vantara Pentaho through 7.x - 8.x contains a reflected Cross-site scripting vulnerability, which allows an authenticated remote users to execute arbitrary JavaScript code. Specifically, the vulnerability lies in the 'type' attribute of…

  • CVE-2020-24669MedJan 29, 2021
    risk 0.35cvss 5.4epss 0.01

    The New Analysis Report in Hitachi Vantara Pentaho through 7.x - 8.x contains a DOM-based Cross-site scripting vulnerability, which allows an authenticated remote users to execute arbitrary JavaScript code. Specifically, the vulnerability lies in the 'Analysis Report…

  • CVE-2020-24666MedJan 29, 2021
    risk 0.35cvss 5.4epss 0.01

    The Analysis Report in Hitachi Vantara Pentaho through 7.x - 8.x contains a stored Cross-site scripting vulnerability, which allows an authenticated remote users to execute arbitrary JavaScript code. Specifically, the vulnerability lies in the 'Display Name' parameter.…

  • CVE-2020-24664MedJan 29, 2021
    risk 0.35cvss 5.4epss 0.01

    The dashboard Editor in Hitachi Vantara Pentaho through 7.x - 8.x contains a reflected Cross-site scripting vulnerability, which allows an authenticated remote users to execute arbitrary JavaScript code. Specifically, the vulnerability lies in the 'pho:title' attribute of…

  • CVE-2017-9298MedMay 29, 2017
    risk 0.35cvss 5.4epss 0.01

    Cross-site scripting vulnerability in Hitachi Device Manager before 8.5.2-01 and Hitachi Replication Manager before 8.5.2-00 allows authenticated remote users to execute arbitrary JavaScript code.

  • CVE-2025-2514MedMay 7, 2026
    risk 0.34cvss 5.3epss 0.00

    Improper restriction of excessive authentication attempts vulnerability in Hitachi Virtual Storage Platform G130, G150, G350, G370, G700, G900, F350, F370, F700, F900, Hitachi Virtual Storage Platform E390, E590, E790, E990, E1090, E390H, E590H, E790H, E1090H, Hitachi Virtual…

  • CVE-2025-5781MedFeb 25, 2026
    risk 0.34cvss 5.2epss 0.00

    Information Exposure Vulnerability in Hitachi Ops Center API Configuration Manager, Hitachi Configuration Manager, Hitachi Device Manager allows Session Hijacking.This issue affects Hitachi Ops Center API Configuration Manager: from 10.0.0-00 before 11.0.5-00; Hitachi…

  • CVE-2026-1772MedFeb 24, 2026
    risk 0.34cvss 5.3epss 0.00

    RTU500 web interface: An unprivileged user can read user management information. The information cannot be accessed via the RTU500 web user interface but requires further tools like browser development utilities to access them without required privileges.

Page 4 of 8