ID

VAR-201309-0572


TITLE

Unknown arbitrary command execution vulnerability in Hitachi JP1 / Automatic Job Management System

Trust: 0.6

sources: CNVD: CNVD-2013-13424

DESCRIPTION

Hitachi JP1 is a solution that monitors the execution of business and centrally manages system content such as OS and applications. Hitachi JP1 / Automatic Job Management System is a set of job management systems from Hitachi, Japan. The system supports scheduling, job error notifications, and visualization of job health. A remote arbitrary command execution vulnerability exists in Hitachi JP1 / Automatic Job Management System. An attacker could use this vulnerability to execute arbitrary commands in the context of an affected application

Trust: 1.35

sources: CNVD: CNVD-2013-13424 // CNNVD: CNNVD-201310-161 // BID: 62750

IOT TAXONOMY

category:['ICS']sub_category: -

Trust: 0.6

sources: CNVD: CNVD-2013-13424

AFFECTED PRODUCTS

vendor:hitachimodel:jp1/automatic job management systemscope: - version: -

Trust: 0.6

vendor:hitachimodel:jp1/automatic job management system managerscope:eqversion:3-0

Trust: 0.3

vendor:hitachimodel:jp1/automatic job management system agentscope:eqversion:3-0

Trust: 0.3

vendor:hitachimodel:jp1/automatic job management system managerscope:eqversion:2-0

Trust: 0.3

vendor:hitachimodel:jp1/automatic job management system light editscope:eqversion:2-0

Trust: 0.3

vendor:hitachimodel:jp1/automatic job management system agentscope:eqversion:2-0

Trust: 0.3

sources: CNVD: CNVD-2013-13424 // BID: 62750

CVSS

SEVERITY

CVSSV2

CVSSV3

CNVD: CNVD-2013-13424
value: HIGH

Trust: 0.6

CNVD: CNVD-2013-13424
severity: HIGH
baseScore: 7.5
vectorString: AV:N/AC:L/AU:N/C:P/I:P/A:P
accessVector: NETWORK
accessComplexity: LOW
authentication: NONE
confidentialityImpact: PARTIAL
integrityImpact: PARTIAL
availabilityImpact: PARTIAL
exploitabilityScore: 10.0
impactScore: 6.4
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 0.6

sources: CNVD: CNVD-2013-13424

THREAT TYPE

remote

Trust: 0.6

sources: CNNVD: CNNVD-201310-161

TYPE

code injection

Trust: 0.6

sources: CNNVD: CNNVD-201310-161

PATCH

title:Patch for Unknown arbitrary command execution vulnerability in Hitachi JP1 / Automatic Job Management Systemurl:https://www.cnvd.org.cn/patchinfo/show/39995

Trust: 0.6

sources: CNVD: CNVD-2013-13424

EXTERNAL IDS

db:BIDid:62750

Trust: 1.5

db:HITACHIid:HS13-023

Trust: 0.9

db:SECUNIAid:55003

Trust: 0.6

db:CNVDid:CNVD-2013-13424

Trust: 0.6

db:CNNVDid:CNNVD-201310-161

Trust: 0.6

sources: CNVD: CNVD-2013-13424 // BID: 62750 // CNNVD: CNNVD-201310-161

REFERENCES

url:http://www.hitachi.co.jp/prod/comp/soft1/global/security/info/vuls/hs13-023/index.html

Trust: 0.9

url:http://secunia.com/advisories/55003/

Trust: 0.6

url:http://www.hitachi.co.jp/prod/comp/soft1/security/info/vuls/hs13-023/index.html

Trust: 0.6

url:http://www.securityfocus.com/bid/62750

Trust: 0.6

url:http://www.hds.com/products/storage-software/hitachi-device-manager.html

Trust: 0.3

sources: CNVD: CNVD-2013-13424 // BID: 62750 // CNNVD: CNNVD-201310-161

CREDITS

The vendor reported this issue.

Trust: 0.3

sources: BID: 62750

SOURCES

db:CNVDid:CNVD-2013-13424
db:BIDid:62750
db:CNNVDid:CNNVD-201310-161

LAST UPDATE DATE

2022-05-17T02:10:39.356000+00:00


SOURCES UPDATE DATE

db:CNVDid:CNVD-2013-13424date:2013-10-09T00:00:00
db:BIDid:62750date:2013-09-30T00:00:00
db:CNNVDid:CNNVD-201310-161date:2013-10-12T00:00:00

SOURCES RELEASE DATE

db:CNVDid:CNVD-2013-13424date:2013-10-09T00:00:00
db:BIDid:62750date:2013-09-30T00:00:00
db:CNNVDid:CNNVD-201310-161date:2013-09-30T00:00:00