Protect yourself against future threats.
-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA256 =========================================================================== AUSCERT External Security Bulletin Redistribution ESB-2019.1298 Multiple Vulnerabilities in Hitachi Infrastructure Analytics Advisor 16 April 2019 =========================================================================== AusCERT Security Bulletin Summary --------------------------------- Product: Hitachi Infrastructure Analytics Advisor Publisher: Hitachi Operating System: Windows Linux variants Impact/Access: Execute Arbitrary Code/Commands -- Remote/Unauthenticated Unauthorised Access -- Remote/Unauthenticated Resolution: Patch/Upgrade CVE Names: CVE-2016-9878 CVE-2016-5007 CVE-2014-0107 Reference: ASB-2018.0279 ASB-2018.0089 ESB-2019.0741 ESB-2019.0544 Original Bulletin: http://www.hitachi.co.jp/Prod/comp/soft1/global/security/info/vuls/hitachi-sec-2019-108/index.html - --------------------------BEGIN INCLUDED TEXT-------------------- Multiple Vulnerabilities in Hitachi Infrastructure Analytics Advisor Update: April 15, 2019 Multiple vulnerabilities have been found in Hitachi Infrastructure Analytics Advisor. Security Information ID hitachi-sec-2019-108 Vulnerability description Multiple vulnerabilities have been found in Hitachi Infrastructure Analytics Advisor. CVE-2014-0107 CVE-2016-5007 CVE-2016-9878 File permission problem Affected products and versions are listed below. Please upgrade your version to the appropriate version. Affected products The information is organized under the following headings: (Example) Product name: Gives the name of the affected product. Version: Platform Gives the affected version. Product name: Hitachi Infrastructure Analytics Advisor(*1)(*2) Version(s): Windows(x64), Linux(x64) 2.0.0-00 or more and less than 4.3.0-00 *1 This product has been discontinued in Japan. *2 Components affected by these vulnerabilities: Data Center Analytics 6.0.0-00 or more and less than 9.3.0-00 Analytics probe 6.0.0-00 or more and less than 9.3.0-00 Fixed products The information is organized under the following headings: (Example) Product name: Gives the name of the fixed product. Version: Platform Gives the fixed version, and release date. Scheduled version: Platform Gives the fixed version scheduled to be released. Product name: Hitachi Infrastructure Analytics Advisor(*1) Version(s): Windows(x64), Linux(x64) 4.3.0-00 April 15, 2019 For details on the fixed products, contact your Hitachi support service representative. Revision history April 15, 2019 This page is released. - --------------------------END INCLUDED TEXT-------------------- You have received this e-mail bulletin as a result of your organisation's registration with AusCERT. The mailing list you are subscribed to is maintained within your organisation, so if you do not wish to continue receiving these bulletins you should contact your local IT manager. If you do not know who that is, please send an email to auscert@auscert.org.au and we will forward your request to the appropriate person. NOTE: Third Party Rights This security bulletin is provided as a service to AusCERT's members. As AusCERT did not write the document quoted above, AusCERT has had no control over its content. The decision to follow or act on information or advice contained in this security bulletin is the responsibility of each user or organisation, and should be considered in accordance with your organisation's site policies and procedures. AusCERT takes no responsibility for consequences which may arise from following or acting on information or advice contained in this security bulletin. NOTE: This is only the original release of the security bulletin. It may not be updated when updates to the original are made. If downloading at a later date, it is recommended that the bulletin is retrieved directly from the author's website to ensure that the information is still current. Contact information for the authors of the original document is included in the Security Bulletin above. If you have any questions or need further information, please contact them directly. Previous advisories and external security bulletins can be retrieved from: https://www.auscert.org.au/bulletins/ =========================================================================== Australian Computer Emergency Response Team The University of Queensland Brisbane Qld 4072 Internet Email: auscert@auscert.org.au Facsimile: (07) 3365 7031 Telephone: (07) 3365 4417 (International: +61 7 3365 4417) AusCERT personnel answer during Queensland business hours which are GMT+10:00 (AEST). On call after hours for member emergencies only. =========================================================================== -----BEGIN PGP SIGNATURE----- Comment: http://www.auscert.org.au/render.html?it=1967 iQIVAwUBXLVIzmaOgq3Tt24GAQiTkw/+LsB3C8u2O0hjemxlYv1TifkD+UDhuoWE gUQD8XWbMRxLCiAZAS5TwsFxfj7XFptM9y1HTlcuEQJJdasa0npVCxW8SG2BCf6c xhMq8SGldfFkQAokN80Ewk5ywOwzQkqnHtnbacqJnuRXcuWgapHByXA7734tmk46 xrOSMD5u3mTvzzfWFdMYaBIwdLRuOvqMHIKzIpyuSYcIFdfvozjJL+LHPWi6IDNU LVu+FX88Q2Mdjsg7kjTw4lHYRexG+X8HXkzgWTkGcFlGvtXmHT1I+DyOyI+2bokt lhixwpSPLYoGs1lSiaZBiIyrwaBU2DKj6TzsnQnsqcbzYDM7efDacF1j2yR3FgwW 4A6wc2CupKE6FUexbViI6FpFj1eMCa2TPP1F+0vpwd4ZqziPlLagwykh9RYz6zof Do1mrnho3nOlZKmSf1Ea6IVXqDVIJ/J+gZXtjCkq4LaPGb9LiLsgd4Xs09mC7aWh 9GaS26LY35RIthVRLrinfmFLGaNBwyMMPL1gsU8DCZI9x7c0Zs4IM+DBfjK5X+Lw +o1rXODO+4tOeZkUPRjjK86jMVL4bHpUT9bxw3zWVPlqqD9GxdINZk20kYTMfljG w6F/xTSenW9UDomzQfBUNazPvdngMo0c08K2DRYgS6iYPO/ilaBfSXtHMIryxRFA dfVlCl6n7Vw= =N5AQ -----END PGP SIGNATURE-----