Lucene search

K
cve[email protected]CVE-2007-3623
HistoryJul 09, 2007 - 4:30 p.m.

CVE-2007-3623

2007-07-0916:30:00
web.nvd.nist.gov
24
cve-2007-3623
hitachi
xss
vulnerability
web script
html
nvd

4.3 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:M/Au:N/C:N/I:P/A:N

5.9 Medium

AI Score

Confidence

High

0.005 Low

EPSS

Percentile

76.6%

Cross-site scripting (XSS) vulnerability in the Hitachi JP1/HiCommand Device Manager, Tiered Storage Manager, Replication Monitor, and GlobalLink Availability Manager before 20070528 allows remote attackers to inject arbitrary web script or HTML via the Expect HTTP header.

Affected configurations

NVD
Node
hitachijp1-hicommand_device_managerMatch02_30solaris
OR
hitachijp1-hicommand_device_managerMatch02_30windows
OR
hitachijp1-hicommand_device_managerMatch05_00solaris
OR
hitachijp1-hicommand_device_managerMatch05_00windows
OR
hitachijp1-hicommand_device_managerMatch05_10linux
OR
hitachijp1-hicommand_device_managerMatch05_50linux
OR
hitachijp1-hicommand_device_managerMatch05_50solaris
OR
hitachijp1-hicommand_device_managerMatch05_50windows
OR
hitachijp1-hicommand_global_link_availability_managerMatch05_00windows
OR
hitachijp1-hicommand_replication_monitorMatch04_00solaris
OR
hitachijp1-hicommand_replication_monitorMatch04_00windows
OR
hitachijp1-hicommand_replication_monitorMatch05_00solaris
OR
hitachijp1-hicommand_replication_monitorMatch05_00windows
OR
hitachijp1-hicommand_replication_monitorMatch05_50solaris
OR
hitachijp1-hicommand_replication_monitorMatch05_50windows
OR
hitachijp1-hicommand_tiered_storage_managerMatch04_00windows
OR
hitachijp1-hicommand_tiered_storage_managerMatch04_30solaris
OR
hitachijp1-hicommand_tiered_storage_managerMatch05_00solaris
OR
hitachijp1-hicommand_tiered_storage_managerMatch05_00windows
OR
hitachijp1-hicommand_tiered_storage_managerMatch05_50solaris
OR
hitachijp1-hicommand_tiered_storage_managerMatch05_50windows

4.3 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:M/Au:N/C:N/I:P/A:N

5.9 Medium

AI Score

Confidence

High

0.005 Low

EPSS

Percentile

76.6%

Related for CVE-2007-3623