First published: Mon May 29 2017(Updated: )
XXE vulnerability in Hitachi Device Manager before 8.5.2-01 and Hitachi Replication Manager before 8.5.2-00 allows authenticated remote users to read arbitrary files.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Hitachi Device Manager | <=8.5.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2017-9295 is classified as a medium to high severity vulnerability due to its ability to allow authenticated remote users to read arbitrary files.
To fix CVE-2017-9295, upgrade Hitachi Device Manager to version 8.5.2-01 or later.
CVE-2017-9295 affects authenticated remote users of Hitachi Device Manager version prior to 8.5.2-01 and Hitachi Replication Manager prior to 8.5.2-00.
CVE-2017-9295 is an XML External Entity (XXE) vulnerability.
Attackers exploiting CVE-2017-9295 can potentially access and read sensitive files on the server.