CVE-2021-35528: Authentication Bypass Vulnerability Vulnerability in Retail Operations Product and Counterparty Settlement and Billing (CSB)
Improper Access Control vulnerability in the application authentication and authorization of Hitachi Energy Retail Operations, Counterparty Settlement and Billing (CSB) allows an attacker to execute a modified signed Java Applet JAR file. A successful exploitation may lead to data extraction or modification of data inside the application. This issue affects: Hitachi Energy Retail Operations 5.7.3 and prior versions. Hitachi Energy Counterparty Settlement and Billing (CSB) 5.7.3 prior versions.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the vulnerability ID for this vulnerability?
The vulnerability ID for this vulnerability is CVE-2021-35528.
What is the severity of CVE-2021-35528?
The severity of CVE-2021-35528 is high with a severity value of 7.1.
What software is affected by CVE-2021-35528?
The Hitachi Energy Retail Operations, Counterparty Settlement and Billing (CSB) software versions up to 5.7.3 are affected by CVE-2021-35528.
How can an attacker exploit CVE-2021-35528?
An attacker can exploit CVE-2021-35528 by executing a modified signed Java Applet JAR file.
Are there any references for CVE-2021-35528?
Yes, you can find references for CVE-2021-35528 at the following links: [Link 1](https://search.abb.com/library/Download.aspx?DocumentID=8DBD000067&LanguageCode=en&DocumentPartId=&Action=Launch), [Link 2](https://search.abb.com/library/Download.aspx?DocumentID=8DBD000068&LanguageCode=en&DocumentPartId=&Action=Launch).