First published: Tue Jun 17 2014(Updated: )
Cross-site request forgery (CSRF) vulnerability in Hitachi Tuning Manager before 7.6.1-06 and 8.x before 8.0.0-04 and JP1/Performance Management - Manager Web Option 07-00 through 07-54 allows remote attackers to hijack the authentication of unspecified victims via unknown vectors.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Hitachi JP1/Performance Management | =07-00 | |
Hitachi JP1/Performance Management | =07-00 | |
Hitachi JP1/Performance Management | =07-54 | |
Hitachi JP1/Performance Management | =07-54 | |
Hitachi Tuning Manager | =6.0.0 | |
Hitachi Tuning Manager | =6.0.0 | |
Hitachi Tuning Manager | =7.1.0 | |
Hitachi Tuning Manager | =7.6.1 | |
Hitachi Tuning Manager | =7.6.1-05 | |
Hitachi Tuning Manager | =8.0.0 | |
Hitachi Tuning Manager | =8.0.0 | |
Hitachi Tuning Manager | =8.0.0-03 | |
Hitachi Tuning Manager | =8.0.0-03 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2014-4188 has been classified as a medium severity vulnerability due to its potential for cross-site request forgery.
To fix CVE-2014-4188, upgrade to the latest version of Hitachi Tuning Manager or JP1/Performance Management that is not affected by the vulnerability.
The affected software includes Hitachi Tuning Manager versions before 7.6.1-06, 8.x before 8.0.0-04, and JP1/Performance Management - Manager Web Option versions 07-00 through 07-54.
CVE-2014-4188 is a cross-site request forgery (CSRF) vulnerability.
Yes, CVE-2014-4188 can allow remote attackers to hijack the authentication of unspecified victims.