VYPR

Vendor CVEs

Hitachi

All CVEs

351 total · sorted by risk
  • CVE-2023-5515MedNov 1, 2023
    risk 0.34cvss 5.3epss 0.00

    The responses for web queries with certain parameters disclose internal path of resources. This information can be used to learn internal structure of the application and to further plot attacks against web servers and deployed web applications.

  • CVE-2023-5514MedNov 1, 2023
    risk 0.34cvss 5.3epss 0.00

    The response messages received from the eSOMS report generation using certain parameter queries with full file path can be abused for enumerating the local file system structure.

  • CVE-2023-3967MedOct 3, 2023
    risk 0.34cvss 5.3epss 0.01

    Allocation of Resources Without Limits or Throttling vulnerability in Hitachi Ops Center Common Services on Linux allows DoS.This issue affects Hitachi Ops Center Common Services: before 10.9.3-00.

  • CVE-2023-1995MedAug 29, 2023
    risk 0.34cvss 5.3epss 0.00

    Insufficient Logging vulnerability in Hitachi HiRDB Server, HiRDB Server With Addtional Function, HiRDB Structured Data Access Facility.This issue affects HiRDB Server: before 09-60-39, before 09-65-23, before 09-66-17, before 10-01-10, before 10-03-12, before 10-04-06,…

  • CVE-2024-2819MedJul 2, 2024
    risk 0.33cvss 5.1epss 0.00

    Incorrect Default Permissions, Improper Preservation of Permissions vulnerability in Hitachi Ops Center Common Services allows File Manipulation.This issue affects Hitachi Ops Center Common Services: before 11.0.2-00.

  • CVE-2021-45446MedNov 2, 2022
    risk 0.33cvss 5.0epss 0.00

    A vulnerability in Hitachi Vantara Pentaho Business Analytics Server versions before 9.2.0.2 and 8.3.0.25 does not cascade the hidden property to the children of the Home folder.  This directory listing provides an attacker with the complete index of all the resources…

  • CVE-2021-40336MedJul 25, 2022
    risk 0.33cvss 5.0epss 0.00

    A vulnerability exists in the http web interface where the web interface does not validate data in an HTTP header. This causes a possible HTTP response splitting, which if exploited could lead an attacker to channel down harmful code into the user’s web browser, such as to…

  • CVE-2021-40335MedJul 25, 2022
    risk 0.33cvss 5.0epss 0.00

    A vulnerability exists in the HTTP web interface where the web interface does not sufficiently verify if a well-formed, valid, consistent request was intentionally provided by the user who submitted the request. This cause a Cross Site Request Forgery (CSRF), which if exploited…

  • CVE-2025-24911MedApr 16, 2025
    risk 0.32cvss 4.9epss 0.00

    Overview   XML documents optionally contain a Document Type Definition (DTD), which, among other features, enables the definition of XML entities. It is possible to define an entity by providing a substitution string in the form of a URI. Once the content of the URI is…

  • CVE-2025-24910MedApr 16, 2025
    risk 0.32cvss 4.9epss 0.00

    Overview   XML documents optionally contain a Document Type Definition (DTD), which, among other features, enables the definition of XML entities. It is possible to define an entity by providing a substitution string in the form of a URI. Once the content of the URI is…

  • CVE-2024-11499MedMar 25, 2025
    risk 0.32cvss 4.9epss 0.00

    A vulnerability exists in RTU500 IEC 60870-4-104 controlled station functionality, that allows an authenticated and authorized attacker to perform a CMU restart. The vulnerability can be triggered if certificates are updated while in use on active connections. The affected CMU…

  • CVE-2024-6696MedFeb 20, 2025
    risk 0.32cvss 4.9epss 0.00

    The product implements access controls via a policy or other feature with the intention to disable or restrict accesses (reads and/or writes) to assets in a system from untrusted agents. However, implemented access controls lack required granularity, which renders the control…

  • CVE-2025-0976MedFeb 25, 2026
    risk 0.31cvss 4.7epss 0.00

    Information Exposure Vulnerability in Hitachi Ops Center API Configuration Manager, Hitachi Configuration Manager.This issue affects Hitachi Ops Center API Configuration Manager: from 10.0.0-00 before 11.0.4-00; Hitachi Configuration Manager: from 8.6.1-00 before 11.0.5-00.

  • CVE-2022-3686MedMar 28, 2023
    risk 0.31cvss 4.8epss 0.01

    A vulnerability exists in a SDM600 endpoint. An attacker could exploit this vulnerability by running multiple parallel requests, the SDM600 web services become busy rendering the application unresponsive. This issue affects: All SDM600 versions prior to version 1.2 FP3 HF4…

  • CVE-2026-3314MedMay 26, 2026
    risk 0.30cvss 4.6epss 0.00

    Missing password field masking vulnerability in Hitachi Ops Center Analyzer (Hitachi Ops Center Analyzer detail view, Hitachi Ops Center Analyzer probe modules), Hitachi Ops Center Analyzer viewpoint, Hitachi Infrastructure Analytics Advisor (Data Center Analytics, Analytics…

  • CVE-2023-49106MedJan 16, 2024
    risk 0.30cvss 4.6epss 0.00

    Missing Password Field Masking vulnerability in Hitachi Device Manager on Windows, Linux (Device Manager Agent component).This issue affects Hitachi Device Manager: before 8.8.5-04.

  • CVE-2025-24909MedApr 16, 2025
    risk 0.29cvss 4.4epss 0.00

    Overview   The software does not neutralize or incorrectly neutralize user-controllable input before it is placed in output that is used as a web page that is served to other users. (CWE-79)   Description   Hitachi Vantara Pentaho Business Analytics…

  • CVE-2025-0757MedApr 16, 2025
    risk 0.29cvss 4.4epss 0.00

    Overview   The software does not neutralize or incorrectly neutralize user-controllable input before it is placed in output that is used as a web page that is served to other users. (CWE-79)   Description   Hitachi Vantara Pentaho Business Analytics Server…

  • CVE-2024-10037MedMar 25, 2025
    risk 0.29cvss 4.4epss 0.00

    A vulnerability exists in the RTU500 web server component that can cause a denial of service to the RTU500 CMU application if a specially crafted message sequence is executed on a WebSocket connection. An attacker must be properly authenticated and the test mode function of…

  • CVE-2024-37360MedFeb 19, 2025
    risk 0.29cvss 4.4epss 0.00

    Hitachi Vantara Pentaho Business Analytics Server - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')   The software does not neutralize or incorrectly neutralize user-controllable input before it is placed in output that is used as a…

  • CVE-2024-22385MedJun 25, 2024
    risk 0.29cvss 4.4epss 0.00

    Incorrect Default Permissions vulnerability in Hitachi Storage Provider for VMware vCenter allows local users to read and write specific files.This issue affects Hitachi Storage Provider for VMware vCenter: from 3.1.0 before 3.7.4.

  • CVE-2023-6833MedApr 23, 2024
    risk 0.29cvss 4.4epss 0.00

    Insertion of Sensitive Information into Log File vulnerability in Hitachi Ops Center Administrator allows local users to gain sensitive information.This issue affects Hitachi Ops Center Administrator: before 11.0.1.

  • CVE-2022-3864MedJan 4, 2024
    risk 0.29cvss 4.5epss 0.00

    A vulnerability exists in the Relion update package signature validation. A tampered update package could cause the IED to restart. After restart the device is back to normal operation. An attacker could exploit the vulnerability by first gaining access to the system with…

  • CVE-2026-2255MedMay 27, 2026
    risk 0.28cvss 4.3epss 0.00

    Hitachi Vantara Pentaho Data Integration & Analytics versions before 10.2.0.6 and 11.0.0.0, including 9.3.x and 8.3.x, expose Hadoop cluster credentials in plain text through the Cluster Test API. Although the user should not see those explicitly, the defect is mitigated by…

  • CVE-2026-1166MedMar 25, 2026
    risk 0.28cvss 4.3epss 0.00

    Open Redirect vulnerability in Hitachi Ops Center Administrator.This issue affects Hitachi Ops Center Administrator: from 10.2.0 before 11.0.8.

  • CVE-2025-3624MedMay 16, 2025
    risk 0.28cvss 4.3epss 0.00

    Missing Authorization vulnerability in Hitachi Ops Center Analyzer (Hitachi Ops Center Analyzer detail view component).This issue affects Hitachi Ops Center Analyzer: from 10.0.0-00 before 11.0.4-00.

  • CVE-2024-9929MedNov 26, 2024
    risk 0.28cvss 4.3epss 0.00

    A vulnerability exists in NSD570 that allows any authenticated user to access all device logs disclosing login information with timestamps.

  • CVE-2024-7941MedAug 27, 2024
    risk 0.28cvss 4.3epss 0.00

    An HTTP parameter may contain a URL value and could cause the web application to redirect the request to the specified URL. By modifying the URL value to a malicious site, an attacker may successfully launch a phishing scam and steal user credentials.

  • CVE-2023-2358MedSep 27, 2023
    risk 0.28cvss 4.3epss 0.00

    Hitachi Vantara Pentaho Business Analytics Server prior to versions 9.5.0.0 and 9.3.0.4, including 8.3.x.x, saves passwords of the Hadoop Copy Files step in plaintext. 

  • CVE-2023-1158MedMay 24, 2023
    risk 0.28cvss 4.3epss 0.00

    Hitachi Vantara Pentaho Business Analytics Server versions before 9.4.0.1 and 9.3.0.3, including 8.3.x expose dashboard prompts to users who are not part of the authorization list. 

  • CVE-2022-4770MedApr 3, 2023
    risk 0.28cvss 4.3epss 0.00

    Hitachi Vantara Pentaho Business Analytics Server prior to versions 9.4.0.0 and 9.3.0.2, including 8.3.x display the full parametrized SQL query in an error message when an invalid character is used within a Pentaho Report (*.prpt). 

  • CVE-2022-4769MedApr 3, 2023
    risk 0.28cvss 4.3epss 0.00

    Hitachi Vantara Pentaho Business Analytics Server prior to versions 9.4.0.0 and 9.3.0.2, including 8.3.x display the target path on host when a file is uploaded with an invalid character in its name. 

  • CVE-2021-31600MedNov 8, 2021
    risk 0.28cvss 4.3epss 0.01

    An issue was discovered in Hitachi Vantara Pentaho through 9.1 and Pentaho Business Intelligence Server through 7.x. They implement a series of web services using the SOAP protocol to allow scripting interaction with the backend server. An authenticated user (regardless of…

  • CVE-2018-21032MedFeb 14, 2020
    risk 0.28cvss 4.3epss 0.01

    A vulnerability in Hitachi Command Suite prior to 8.7.1-00 and Hitachi Automation Director prior to 8.5.0-00 allow authenticated remote users to expose technical information through error messages. Hitachi Command Suite includes Hitachi Device Manager and Hitachi Compute Systems…

  • CVE-2024-28024MedJun 11, 2024
    risk 0.27cvss 4.1epss 0.00

    A vulnerability exists in the FOXMAN-UN/UNEM in which sensitive information is stored in cleartext within a resource that might be accessible to another control sphere.

  • CVE-2021-40337MedJan 25, 2022
    risk 0.27cvss 4.2epss 0.00

    Cross-site Scripting (XSS) vulnerability in Hitachi Energy LinkOne allows an attacker that manages to exploit the vulnerability can take advantage to exploit multiple web attacks and stole sensitive information. This issue affects: Hitachi Energy LinkOne 3.20; 3.22; 3.23; 3.24;…

  • CVE-2023-1711MedMay 30, 2023
    risk 0.26cvss 4.0epss 0.00

    A vulnerability exists in a FOXMAN-UN and UNEM logging component, it only affects systems that use remote authentication to the network elements. If exploited an attacker could obtain confidential information. List of CPEs: * cpe:2.3:a:hitachienergy:foxman_un:R9C:*:*:*:*:*…

  • CVE-2025-27525LowMay 15, 2025
    risk 0.25cvss 3.9epss 0.00

    Information Exposure vulnerability in Hitachi JP1/IT Desktop Management 2 - Smart Device Manager on Windows.This issue affects JP1/IT Desktop Management 2 - Smart Device Manager: from 12-00 before 12-00-08, from 11-10 through 11-10-08, from 11-00 through 11-00-05, from 10-50…

  • CVE-2022-43772LowApr 3, 2023
    risk 0.25cvss 3.8epss 0.00

    Hitachi Vantara Pentaho Business Analytics Server versions before 9.4.0.0 and 9.3.0.1, including 8.3.x with the Big Data Plugin expose the username and password of clusters in clear text into system logs. 

  • CVE-2021-40340LowJan 28, 2022
    risk 0.24cvss 3.7epss 0.01

    Information Exposure vulnerability in Hitachi Energy LinkOne application, due to a misconfiguration in the ASP server exposes server and ASP.net information, an attacker that manages to exploit this vulnerability can use the exposed information as a reconnaissance for further…

  • CVE-2021-40339LowJan 28, 2022
    risk 0.24cvss 3.7epss 0.01

    Configuration vulnerability in Hitachi Energy LinkOne application due to the lack of HTTP Headers, allows an attacker that manages to exploit this vulnerability to retrieve sensitive information. This issue affects: Hitachi Energy LinkOne 3.20; 3.22; 3.23; 3.24; 3.25; 3.26.

  • CVE-2021-40338LowJan 28, 2022
    risk 0.24cvss 3.7epss 0.01

    Hitachi Energy LinkOne product, has a vulnerability due to a web server misconfiguration, that enables debug mode and reveals the full path of the filesystem directory when an attacker generates errors during a query operation. This issue affects: Hitachi Energy LinkOne 3.20;…

  • CVE-2022-34881LowDec 6, 2022
    risk 0.21cvss 3.3epss 0.00

    Generation of Error Message Containing Sensitive Information vulnerability in Hitachi JP1/Automatic Operation allows local users to gain sensitive information. This issue affects JP1/Automatic Operation: from 10-00 through 10-54-03, from 11-00 before 11-51-09, from 12-00 before…

  • CVE-2024-41156LowOct 29, 2024
    risk 0.18cvss 2.7epss 0.00

    Profile files from TRO600 series radios are extracted in plain-text and encrypted file formats. Profile files provide potential attackers valuable configuration information about the Tropos network. Profiles can only be exported by authenticated users with higher privilege of…

  • CVE-2023-2622LowNov 1, 2023
    risk 0.18cvss 2.7epss 0.00

    Authenticated clients can read arbitrary files on the MAIN Computer system using the remote procedure call (RPC) of the InspectSetup service endpoint. The low privilege client is then allowed to read arbitrary files that they do not have authorization to read.

  • CVE-2021-34685LowNov 8, 2021
    risk 0.18cvss 2.7epss 0.02

    UploadService in Hitachi Vantara Pentaho Business Analytics through 9.1 does not properly verify uploaded user files, which allows an authenticated user to upload various files of different file types. Specifically, a .jsp file is not allowed, but a .jsp. file is allowed (and…

  • CVE-2005-0356May 31, 2005
    risk 0.10cvss epss 0.83

    Multiple TCP implementations with Protection Against Wrapped Sequence Numbers (PAWS) with the timestamps option enabled allow remote attackers to cause a denial of service (connection loss) via a spoofed packet with a large timer value, which causes the host to discard later…

  • CVE-2005-3164Oct 6, 2005
    risk 0.01cvss epss 0.07

    The AJP connector in Apache Tomcat 4.0.1 through 4.0.6 and 4.1.0 through 4.1.36, as used in Hitachi Cosminexus Application Server and standalone, does not properly handle when a connection is broken before request body data is sent in a POST request, which can lead to an…

  • CVE-2003-0564Dec 1, 2003
    risk 0.01cvss epss 0.08

    Multiple vulnerabilities in multiple vendor implementations of the Secure/Multipurpose Internet Mail Extensions (S/MIME) protocol allow remote attackers to cause a denial of service and possibly execute arbitrary code via an S/MIME email message containing certain unexpected…

  • CVE-2025-7386MedJun 29, 2026
    risk 0.00cvss 6.8epss 0.00

    Information exposure vulnerability in Hitachi Storage Navigator. This issue affects Hitachi Virtual Storage Platform 5100, 5200, 5500, 5600, 5100H, 5200H, 5500H, 5600H, VX8: before DKCMAIN Ver. 90-09-24-00/00, SVP Ver. 90-09-24/00, before DKCMAIN Ver. 90-08-86-00/00, SVP Ver.…

Page 5 of 8