ID

VAR-201310-0807


TITLE

Arbitrary Commands Execution Vulnerability in JP1/Automatic Job Management System 3 and JP1/Automatic Job Management System 2

Trust: 0.8

sources: JVNDB: JVNDB-2013-004409

DESCRIPTION

The JP1/Automatic Job Management System 3 and JP1/Automatic Job Management System 2 contain a vulnerability where arbitrary commands may be executed when they receive request messages from unexpected hosts in the network.Malicious users can exploit this vulnerability to execute arbitrary commands by sending request messages from an unexpected host.

Trust: 0.8

sources: JVNDB: JVNDB-2013-004409

AFFECTED PRODUCTS

vendor:hitachimodel:jp1/automatic job management system 2scope:eqversion:- agent

Trust: 0.8

vendor:hitachimodel:jp1/automatic job management system 2scope:eqversion:- light edition

Trust: 0.8

vendor:hitachimodel:jp1/automatic job management system 2scope:eqversion:- manager

Trust: 0.8

vendor:hitachimodel:jp1/automatic job management system 3scope:eqversion:- agent

Trust: 0.8

vendor:hitachimodel:jp1/automatic job management system 3scope:eqversion:- manager

Trust: 0.8

sources: JVNDB: JVNDB-2013-004409

CVSS

SEVERITY

CVSSV2

CVSSV3

VENDOR: JVNDB-2013-004409
value: HIGH

Trust: 0.8

VENDOR: JVNDB-2013-004409
severity: HIGH
baseScore: 8.3
vectorString: AV:A/AC:L/AU:N/C:C/I:C/A:C
accessVector: ADJACENT NETWORK
accessComplexity: LOW
authentication: NONE
confidentialityImpact: COMPLETE
integrityImpact: COMPLETE
availabilityImpact: COMPLETE
exploitabilityScore: NONE
impactScore: NONE
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 0.8

sources: JVNDB: JVNDB-2013-004409

CONFIGURATIONS

sources: JVNDB: JVNDB-2013-004409

PATCH

title:HS13-023url:http://www.hitachi.co.jp/prod/comp/soft1/global/security/info/vuls/hs13-023/index.html

Trust: 0.8

sources: JVNDB: JVNDB-2013-004409

EXTERNAL IDS

db:JVNDBid:JVNDB-2013-004409

Trust: 0.8

sources: JVNDB: JVNDB-2013-004409

SOURCES

db:JVNDBid:JVNDB-2013-004409

LAST UPDATE DATE

2022-05-04T09:35:03.661000+00:00


SOURCES UPDATE DATE

db:JVNDBid:JVNDB-2013-004409date:2013-10-03T00:00:00

SOURCES RELEASE DATE

db:JVNDBid:JVNDB-2013-004409date:2013-10-03T00:00:00