4.3

CVE-2007-3623

Cross-site scripting (XSS) vulnerability in the Hitachi JP1/HiCommand Device Manager, Tiered Storage Manager, Replication Monitor, and GlobalLink Availability Manager before 20070528 allows remote attackers to inject arbitrary web script or HTML via the Expect HTTP header.

Data is provided by the National Vulnerability Database (NVD)
HitachiJp1-hicommand Device Manager Version02_30 Editionsolaris
HitachiJp1-hicommand Device Manager Version02_30 Editionwindows
HitachiJp1-hicommand Device Manager Version05_00 Editionsolaris
HitachiJp1-hicommand Device Manager Version05_00 Editionwindows
HitachiJp1-hicommand Device Manager Version05_10 Editionlinux
HitachiJp1-hicommand Device Manager Version05_50 Editionlinux
HitachiJp1-hicommand Device Manager Version05_50 Editionsolaris
HitachiJp1-hicommand Device Manager Version05_50 Editionwindows
HitachiJp1-hicommand Replication Monitor Version04_00 Editionsolaris
HitachiJp1-hicommand Replication Monitor Version04_00 Editionwindows
HitachiJp1-hicommand Replication Monitor Version05_00 Editionsolaris
HitachiJp1-hicommand Replication Monitor Version05_00 Editionwindows
HitachiJp1-hicommand Replication Monitor Version05_50 Editionsolaris
HitachiJp1-hicommand Replication Monitor Version05_50 Editionwindows
HitachiJp1-hicommand Tiered Storage Manager Version04_00 Editionwindows
HitachiJp1-hicommand Tiered Storage Manager Version04_30 Editionsolaris
HitachiJp1-hicommand Tiered Storage Manager Version05_00 Editionsolaris
HitachiJp1-hicommand Tiered Storage Manager Version05_00 Editionwindows
HitachiJp1-hicommand Tiered Storage Manager Version05_50 Editionsolaris
HitachiJp1-hicommand Tiered Storage Manager Version05_50 Editionwindows
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 0.77% 0.727
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
nvd@nist.gov 4.3 8.6 2.9
AV:N/AC:M/Au:N/C:N/I:P/A:N