First published: Tue Jun 17 2014(Updated: )
Cross-site scripting (XSS) vulnerability in Hitachi Tuning Manager before 7.6.1-06 and 8.x before 8.0.0-04 and JP1/Performance Management - Manager Web Option 07-00 through 07-54 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Hitachi Jp1\/performance Management-manager Web Option | =07-00 | |
Hitachi Jp1\/performance Management-manager Web Option | =07-00 | |
Hitachi Jp1\/performance Management-manager Web Option | =07-54 | |
Hitachi Jp1\/performance Management-manager Web Option | =07-54 | |
Hitachi Tuning Manager | =6.0.0 | |
Hitachi Tuning Manager | =6.0.0 | |
Hitachi Tuning Manager | =7.1.0 | |
Hitachi Tuning Manager | =7.6.1 | |
Hitachi Tuning Manager | =7.6.1-05 | |
Hitachi Tuning Manager | =8.0.0 | |
Hitachi Tuning Manager | =8.0.0 | |
Hitachi Tuning Manager | =8.0.0-03 | |
Hitachi Tuning Manager | =8.0.0-03 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2014-4189 is classified as a medium severity vulnerability due to its potential impact on web applications.
To fix CVE-2014-4189, update to the latest versions of Hitachi Tuning Manager or JP1/Performance Management - Manager Web Option as specified by the vendor.
CVE-2014-4189 affects Hitachi Tuning Manager prior to version 7.6.1-06 and 8.x before 8.0.0-04, as well as JP1/Performance Management - Manager Web Option versions 07-00 through 07-54.
CVE-2014-4189 is a cross-site scripting (XSS) vulnerability allowing remote attackers to inject malicious scripts.
Users of the affected versions of Hitachi Tuning Manager and JP1/Performance Management - Manager Web Option can be impacted by CVE-2014-4189 if exploited.