CVE-2021-28052
A tenant administrator Hitachi Content Platform (HCP) may modify the configuration in another tenant without authorization, potentially allowing unauthorized access to data in the other tenant.
Does this matter?
Lower severity and a low EPSS score (0.70%). Track it; it rarely justifies an emergency change on its own.
Description
A tenant administrator Hitachi Content Platform (HCP) may modify the configuration in another tenant without authorization, potentially allowing unauthorized access to data in the other tenant. Also, a tenant user (non-administrator) may view configuration in another tenant without authorization. This issue affects: Hitachi Vantara Hitachi Content Platform versions prior to 8.3.7; 9.0.0 versions prior to 9.2.3.
- CVSS 3.1
- 4.9 MEDIUMCVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N
- EPSS
- 0.70% probability · 51th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-264, CWE-862
- Affected
- hitach/vantara
- Source
- hirt@hitachi.co.jp
References
- https://knowledge.hitachivantara.com/Security/HCP_Multitenancy_VulnerabilityVendor Advisory
- https://www.hitachi.com/hirt/hitachi-sec/2021/604.htmlVendor Advisory
- https://knowledge.hitachivantara.com/Security/HCP_Multitenancy_VulnerabilityVendor Advisory
- https://www.hitachi.com/hirt/hitachi-sec/2021/604.htmlVendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.