6.8

CVE-2014-4188

Cross-site request forgery (CSRF) vulnerability in Hitachi Tuning Manager before 7.6.1-06 and 8.x before 8.0.0-04 and JP1/Performance Management - Manager Web Option 07-00 through 07-54 allows remote attackers to hijack the authentication of unspecified victims via unknown vectors.

Data is provided by the National Vulnerability Database (NVD)
HitachiTuning Manager Version6.0.0 SwPlatformsolaris
HitachiTuning Manager Version6.0.0 SwPlatformwindows
HitachiTuning Manager Version7.1.0 SwPlatformlinux_kernel
HitachiTuning Manager Version7.6.1 SwPlatformsolaris
HitachiTuning Manager Version7.6.1 Update05 SwPlatformsolaris
HitachiTuning Manager Version8.0.0 SwPlatformlinux_kernel
HitachiTuning Manager Version8.0.0 SwPlatformwindows
HitachiTuning Manager Version8.0.0 Update03 SwPlatformlinux_kernel
HitachiTuning Manager Version8.0.0 Update03 SwPlatformwindows
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 0.15% 0.323
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
nvd@nist.gov 6.8 8.6 6.4
AV:N/AC:M/Au:N/C:P/I:P/A:P
CWE-352 Cross-Site Request Forgery (CSRF)

The web application does not, or can not, sufficiently verify whether a well-formed, valid, consistent request was intentionally provided by the user who submitted the request.