Hitachi Command Suite Multiple Products Cross-Site Scripting and Denial of Service Vulnerabilities
10 Apr. 2012
Summary
Multiple Hitachi Command Suite products are prone to a cross-site scripting vulnerability and a denial-of-service vulnerability because they fail to properly sanitize user-supplied input.
An attacker may leverage these issues to cause denial-of-service conditions or to execute arbitrary script code in the browser of an unsuspecting user in the context of the affected site. This may allow the attacker to steal cookie-based authentication credentials and to launch other attacks.
Vendor Status:
Currently, we are not aware of any vendor-supplied patches.