CVE-2021-28052: Hitachi Content Platform Information Disclosure Vulnerability
A tenant administrator Hitachi Content Platform (HCP) may modify the configuration in another tenant without authorization, potentially allowing unauthorized access to data in the other tenant. Also, a tenant user (non-administrator) may view configuration in another tenant without authorization. This issue affects: Hitachi Vantara Hitachi Content Platform versions prior to 8.3.7; 9.0.0 versions prior to 9.2.3.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2021-28052?
CVE-2021-28052 is rated as a critical severity vulnerability due to its potential impact on data confidentiality across tenants.
How do I fix CVE-2021-28052?
To mitigate CVE-2021-28052, ensure that tenant administrators are restricted from modifying configurations in other tenants and review user permissions accordingly.
Who is affected by CVE-2021-28052?
CVE-2021-28052 affects Hitachi Vantara users operating on specific versions of the Hitachi Content Platform.
Can tenant users view configurations from other tenants due to CVE-2021-28052?
Yes, tenant users may be able to view configurations in other tenants without proper authorization due to CVE-2021-28052.
What are the implications of CVE-2021-28052 for data security?
CVE-2021-28052 allows unauthorized access to configurations, potentially leading to exposure of sensitive data between tenants.