CVE-2017-9295: XEE
Published May 29, 2017
·Updated
XXE vulnerability in Hitachi Device Manager before 8.5.2-01 and Hitachi Replication Manager before 8.5.2-00 allows authenticated remote users to read arbitrary files.
Affected Software
1 affected component
Hitachi Device Manager<=8.5.2
Event History
May 29, 2017
CVE Published
via MITRE·06:00 PM
Data Sourced
via MITRE·06:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2017-9295?
CVE-2017-9295 is classified as a medium to high severity vulnerability due to its ability to allow authenticated remote users to read arbitrary files.
2
How do I fix CVE-2017-9295?
To fix CVE-2017-9295, upgrade Hitachi Device Manager to version 8.5.2-01 or later.
3
Who is affected by CVE-2017-9295?
CVE-2017-9295 affects authenticated remote users of Hitachi Device Manager version prior to 8.5.2-01 and Hitachi Replication Manager prior to 8.5.2-00.
4
What type of vulnerability is CVE-2017-9295?
CVE-2017-9295 is an XML External Entity (XXE) vulnerability.
5
What can attackers do with CVE-2017-9295?
Attackers exploiting CVE-2017-9295 can potentially access and read sensitive files on the server.