First published: Mon Jul 09 2007(Updated: )
Cross-site scripting (XSS) vulnerability in the Hitachi JP1/HiCommand Device Manager, Tiered Storage Manager, Replication Monitor, and GlobalLink Availability Manager before 20070528 allows remote attackers to inject arbitrary web script or HTML via the Expect HTTP header.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Hitachi Jp1-hicommand Device Manager | =05_50 | |
Hitachi Jp1-hicommand Replication Monitor | =04_00 | |
Hitachi Jp1-hicommand Replication Monitor | =05_00 | |
Hitachi Jp1-hicommand Tiered Storage Manager | =05_50 | |
Hitachi Jp1-hicommand Replication Monitor | =05_50 | |
Hitachi Jp1-hicommand Tiered Storage Manager | =05_50 | |
Hitachi Jp1-hicommand Device Manager | =05_00 | |
Hitachi Jp1-hicommand Device Manager | =02_30 | |
Hitachi Jp1-hicommand Device Manager | =05_50 | |
Hitachi Jp1-hicommand Replication Monitor | =05_50 | |
Hitachi Jp1-hicommand Tiered Storage Manager | =05_00 | |
Hitachi Jp1-hicommand Replication Monitor | =05_00 | |
Hitachi Jp1-hicommand Tiered Storage Manager | =05_00 | |
Hitachi Jp1-hicommand Global Link Availability Manager | =05_00 | |
Hitachi Jp1-hicommand Tiered Storage Manager | =04_30 | |
Hitachi Jp1-hicommand Device Manager | =02_30 | |
Hitachi Jp1-hicommand Replication Monitor | =04_00 | |
Hitachi Jp1-hicommand Device Manager | =05_10 | |
Hitachi Jp1-hicommand Tiered Storage Manager | =04_00 | |
Hitachi Jp1-hicommand Device Manager | =05_50 | |
Hitachi Jp1-hicommand Device Manager | =05_00 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2007-3623 has a medium severity rating due to its potential to allow cross-site scripting attacks.
To fix CVE-2007-3623, ensure that you update the affected software to the versions released after May 28, 2007.
CVE-2007-3623 affects Hitachi JP1/HiCommand Device Manager, Tiered Storage Manager, Replication Monitor, and GlobalLink Availability Manager prior to the specified version updates.
CVE-2007-3623 is classified as a cross-site scripting (XSS) vulnerability.
Yes, CVE-2007-3623 can potentially affect web applications using the vulnerable Hitachi software, allowing attackers to inject malicious scripts.