ID

VAR-201706-1152


TITLE

Cross-site Scripting Vulnerability in multiple Hitachi products

Trust: 0.8

sources: JVNDB: JVNDB-2017-002225

DESCRIPTION

A cross-site scripting vulnerability was found in uCosminexus Portal Framework, Groupmax Collaboration, Hitachi Navigation Platform and JP1/Navigation Platform. Remote users can exploit this vulnerability to execute malicious scripts.

Trust: 0.8

sources: JVNDB: JVNDB-2017-002225

AFFECTED PRODUCTS

vendor:hitachimodel:groupmax collaboration portalscope: - version: -

Trust: 0.8

vendor:hitachimodel:groupmax collaboration web clientscope:eqversion:- forum/file sharing

Trust: 0.8

vendor:hitachimodel:groupmax collaboration web client - mail/schedulescope: - version: -

Trust: 0.8

vendor:hitachimodel:navigation platformscope: - version: -

Trust: 0.8

vendor:hitachimodel:navigation platformscope:eqversion:for developers

Trust: 0.8

vendor:hitachimodel:jp1/integrated managementscope:eqversion:- navigation platform

Trust: 0.8

vendor:hitachimodel:jp1/navigation platformscope: - version: -

Trust: 0.8

vendor:hitachimodel:jp1/navigation platformscope:eqversion:for developers

Trust: 0.8

vendor:hitachimodel:ucosminexus collaboration portalscope: - version: -

Trust: 0.8

vendor:hitachimodel:ucosminexus collaboration portalscope:eqversion:- forum/file sharing

Trust: 0.8

vendor:hitachimodel:ucosminexus navigationscope:eqversion:developer

Trust: 0.8

vendor:hitachimodel:ucosminexus navigation platformscope: - version: -

Trust: 0.8

vendor:hitachimodel:ucosminexus navigation platformscope:eqversion:- authoring license

Trust: 0.8

vendor:hitachimodel:ucosminexus navigation platformscope:eqversion:- user license

Trust: 0.8

vendor:hitachimodel:ucosminexus portal frameworkscope: - version: -

Trust: 0.8

vendor:hitachimodel:ucosminexus portal frameworkscope:eqversion:- light

Trust: 0.8

sources: JVNDB: JVNDB-2017-002225

CVSS

SEVERITY

CVSSV2

CVSSV3

VENDOR: JVNDB-2017-002225
value: MEDIUM

Trust: 0.8

VENDOR: JVNDB-2017-002225
severity: MEDIUM
baseScore: 4.3
vectorString: AV:N/AC:M/AU:N/C:N/I:P/A:N
accessVector: NETWORK
accessComplexity: MEDIUM
authentication: NONE
confidentialityImpact: NONE
integrityImpact: PARTIAL
availabilityImpact: NONE
exploitabilityScore: NONE
impactScore: NONE
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 0.8

VENDOR: JVNDB-2017-002225
baseSeverity: MEDIUM
baseScore: 4.7
vectorString: CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:N/I:L/A:N
attackVector: NETWORK
attackComplexity: LOW
privilegesRequired: NONE
userInteraction: REQUIRED
scope: CHANGED
confidentialityImpact: NONE
integrityImpact: LOW
availabilityImpact: NONE
exploitabilityScore: NONE
impactScore: NONE
version: 3.0

Trust: 0.8

sources: JVNDB: JVNDB-2017-002225

CONFIGURATIONS

sources: JVNDB: JVNDB-2017-002225

PATCH

title:hitachi-sec-2017-104url:http://www.hitachi.co.jp/prod/comp/soft1/global/security/info/vuls/hitachi-sec-2017-104/index.html

Trust: 0.8

sources: JVNDB: JVNDB-2017-002225

EXTERNAL IDS

db:JVNDBid:JVNDB-2017-002225

Trust: 0.8

sources: JVNDB: JVNDB-2017-002225

SOURCES

db:JVNDBid:JVNDB-2017-002225

LAST UPDATE DATE

2022-05-04T09:17:30.548000+00:00


SOURCES UPDATE DATE

db:JVNDBid:JVNDB-2017-002225date:2017-06-30T00:00:00

SOURCES RELEASE DATE

db:JVNDBid:JVNDB-2017-002225date:2017-06-30T00:00:00