CVE-2018-21026

A vulnerability in Hitachi Command Suite 7.x and 8.x before 8.6.5-00 allows an unauthenticated remote user to read internal information.
Configurations

Configuration 1 (hide)

AND
cpe:2.3:a:hitachi:device_manager:*:*:*:*:*:*:*:*
OR cpe:2.3:o:linux:linux_kernel:-:*:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:*:*
cpe:2.3:o:oracle:solaris:-:*:*:*:*:*:*:*

Configuration 2 (hide)

AND
cpe:2.3:a:hitachi:tiered_storage_manager:*:*:*:*:*:*:*:*
OR cpe:2.3:o:linux:linux_kernel:-:*:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:*:*
cpe:2.3:o:oracle:solaris:-:*:*:*:*:*:*:*

Configuration 3 (hide)

AND
cpe:2.3:a:hitachi:replication_manager:*:*:*:*:*:*:*:*
OR cpe:2.3:o:linux:linux_kernel:-:*:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:*:*
cpe:2.3:o:oracle:solaris:-:*:*:*:*:*:*:*

Configuration 4 (hide)

AND
cpe:2.3:a:hitachi:tuning_manager:*:*:*:*:*:*:*:*
OR cpe:2.3:o:linux:linux_kernel:-:*:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:*:*

Configuration 5 (hide)

AND
cpe:2.3:a:hitachi:compute_systems_manager:*:*:*:*:*:*:*:*
OR cpe:2.3:o:linux:linux_kernel:-:*:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:*:*

History

21 Nov 2024, 04:02

Type Values Removed Values Added
References () http://www.hitachi.co.jp/Prod/comp/soft1/global/security/info/index.html - Vendor Advisory () http://www.hitachi.co.jp/Prod/comp/soft1/global/security/info/index.html - Vendor Advisory
References () https://www.hitachi.co.jp/Prod/comp/soft1/global/security/info/vuls/hitachi-sec-2019-124/ - Vendor Advisory () https://www.hitachi.co.jp/Prod/comp/soft1/global/security/info/vuls/hitachi-sec-2019-124/ - Vendor Advisory

Information

Published : 2019-11-12 18:15

Updated : 2024-11-21 04:02


NVD link : CVE-2018-21026

Mitre link : CVE-2018-21026

CVE.ORG link : CVE-2018-21026


JSON object : View

Products Affected

oracle

  • solaris

hitachi

  • replication_manager
  • compute_systems_manager
  • tuning_manager
  • tiered_storage_manager
  • device_manager

linux

  • linux_kernel

microsoft

  • windows
CWE
CWE-200

Exposure of Sensitive Information to an Unauthorized Actor