Search

Find a vulnerability

Search criteria

    5 vulnerabilities found for Cosminexus Component Container by Hitachi

    CVE-2026-71377 (GCVE-0-2026-71377)

    Vulnerability from cvelistv5 – Published: 2026-09-08 08:15 – Updated: 2026-09-08 12:23
    VLAI
    Title
    Command Argument Injection Vulnerability in Cosminexus Component Container
    Summary
    Command Argument Injection Vulnerability in Cosminexus Component Container. This issue affects Cosminexus Component Container: from 11-70-01 before 11-70-03, from 11-60 before 11-60-03, from 11-50 through 11-50-03, from 11-40 through 11-40-03, from 11-30 through 11-30-08, from 11-20 before 11-20-10, from 11-10 through 11-10-11, from 11-00 through 11-00-12, from 09-87 before 09-87-10, from 09-80 through 09-80-04, from 09-70 before 09-70-28, from 09-50 through 09-50-22, and from 09-00 through 09-00-18.
    SSVC
    Exploitation: none Automatable: yes Technical Impact: total
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2026-09-08 12:23 UTC
    CWE
    • CWE-88 - Improper neutralization of argument delimiters in a command ('argument injection')
    References
    Impacted products
    Vendor Product Version
    Hitachi Cosminexus Component Container Affected: 11-70-01 , < 11-70-03 (custom)
    Affected: 11-60 , < 11-60-03 (custom)
    Affected: 11-50 , ≤ 11-50-03 (custom)
    Affected: 11-40 , ≤ 11-40-03 (custom)
    Affected: 11-30 , ≤ 11-30-08 (custom)
    Affected: 11-20 , < 11-20-10 (custom)
    Affected: 11-10 , ≤ 11-10-11 (custom)
    Affected: 11-00 , ≤ 11-00-12 (custom)
    Affected: 09-87 , < 09-87-10 (custom)
    Affected: 09-80 , ≤ 09-80-04 (custom)
    Affected: 09-70 , < 09-70-28 (custom)
    Affected: 09-50 , ≤ 09-50-22 (custom)
    Affected: 09-00 , ≤ 09-00-18 (custom)
    Create a notification for this product.
    Date Public
    2026-09-08 08:02
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2026-71377",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "yes"
                      },
                      {
                        "Technical Impact": "total"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2026-09-08T12:23:07.679018Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2026-09-08T12:23:16.192Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "defaultStatus": "unaffected",
              "platforms": [
                "Windows"
              ],
              "product": "Cosminexus Component Container",
              "vendor": "Hitachi",
              "versions": [
                {
                  "changes": [
                    {
                      "at": "11-70-03",
                      "status": "unaffected"
                    }
                  ],
                  "lessThan": "11-70-03",
                  "status": "affected",
                  "version": "11-70-01",
                  "versionType": "custom"
                },
                {
                  "changes": [
                    {
                      "at": "11-60-03",
                      "status": "unaffected"
                    }
                  ],
                  "lessThan": "11-60-03",
                  "status": "affected",
                  "version": "11-60",
                  "versionType": "custom"
                },
                {
                  "lessThanOrEqual": "11-50-03",
                  "status": "affected",
                  "version": "11-50",
                  "versionType": "custom"
                },
                {
                  "lessThanOrEqual": "11-40-03",
                  "status": "affected",
                  "version": "11-40",
                  "versionType": "custom"
                },
                {
                  "lessThanOrEqual": "11-30-08",
                  "status": "affected",
                  "version": "11-30",
                  "versionType": "custom"
                },
                {
                  "changes": [
                    {
                      "at": "11-20-10",
                      "status": "unaffected"
                    }
                  ],
                  "lessThan": "11-20-10",
                  "status": "affected",
                  "version": "11-20",
                  "versionType": "custom"
                },
                {
                  "lessThanOrEqual": "11-10-11",
                  "status": "affected",
                  "version": "11-10",
                  "versionType": "custom"
                },
                {
                  "lessThanOrEqual": "11-00-12",
                  "status": "affected",
                  "version": "11-00",
                  "versionType": "custom"
                },
                {
                  "changes": [
                    {
                      "at": "09-87-10",
                      "status": "unaffected"
                    }
                  ],
                  "lessThan": "09-87-10",
                  "status": "affected",
                  "version": "09-87",
                  "versionType": "custom"
                },
                {
                  "lessThanOrEqual": "09-80-04",
                  "status": "affected",
                  "version": "09-80",
                  "versionType": "custom"
                },
                {
                  "changes": [
                    {
                      "at": "09-70-28",
                      "status": "unaffected"
                    }
                  ],
                  "lessThan": "09-70-28",
                  "status": "affected",
                  "version": "09-70",
                  "versionType": "custom"
                },
                {
                  "lessThanOrEqual": "09-50-22",
                  "status": "affected",
                  "version": "09-50",
                  "versionType": "custom"
                },
                {
                  "lessThanOrEqual": "09-00-18",
                  "status": "affected",
                  "version": "09-00",
                  "versionType": "custom"
                }
              ]
            }
          ],
          "datePublic": "2026-09-08T08:02:00.000Z",
          "descriptions": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "Command Argument Injection Vulnerability in Cosminexus Component Container.\u003cp\u003eThis issue affects Cosminexus Component Container: from 11-70-01 before 11-70-03, from 11-60 before 11-60-03, from 11-50 through 11-50-03, from 11-40 through 11-40-03, from 11-30 through 11-30-08, from 11-20 before 11-20-10, from 11-10 through 11-10-11, from 11-00 through 11-00-12, from 09-87 before 09-87-10, from 09-80 through 09-80-04, from 09-70 before 09-70-28, from 09-50 through 09-50-22, and from 09-00 through 09-00-18.\u003c/p\u003e"
                }
              ],
              "value": "Command Argument Injection Vulnerability in Cosminexus Component Container.\n\nThis issue affects Cosminexus Component Container: from 11-70-01 before 11-70-03, from 11-60 before 11-60-03, from 11-50 through 11-50-03, from 11-40 through 11-40-03, from 11-30 through 11-30-08, from 11-20 before 11-20-10, from 11-10 through 11-10-11, from 11-00 through 11-00-12, from 09-87 before 09-87-10, from 09-80 through 09-80-04, from 09-70 before 09-70-28, from 09-50 through 09-50-22, and from 09-00 through 09-00-18."
            }
          ],
          "impacts": [
            {
              "capecId": "CAPEC-88",
              "descriptions": [
                {
                  "lang": "en",
                  "value": "CAPEC-88 OS Command Injection"
                }
              ]
            }
          ],
          "metrics": [
            {
              "cvssV3_1": {
                "attackComplexity": "LOW",
                "attackVector": "NETWORK",
                "availabilityImpact": "HIGH",
                "baseScore": 9.8,
                "baseSeverity": "CRITICAL",
                "confidentialityImpact": "HIGH",
                "integrityImpact": "HIGH",
                "privilegesRequired": "NONE",
                "scope": "UNCHANGED",
                "userInteraction": "NONE",
                "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
                "version": "3.1"
              },
              "format": "CVSS",
              "scenarios": [
                {
                  "lang": "en",
                  "value": "GENERAL"
                }
              ]
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-88",
                  "description": "CWE-88 Improper neutralization of argument delimiters in a command (\u0027argument injection\u0027)",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-09-08T08:15:00.929Z",
            "orgId": "50d0f415-c707-4733-9afc-8f6c0e9b3f82",
            "shortName": "Hitachi"
          },
          "references": [
            {
              "tags": [
                "vendor-advisory"
              ],
              "url": "https://www.hitachi.com/products/it/software/security/info/vuls/hitachi-sec-2026-133/index.html"
            }
          ],
          "source": {
            "advisory": "hitachi-sec-2026-133",
            "discovery": "UNKNOWN"
          },
          "title": "Command Argument Injection Vulnerability in Cosminexus Component Container",
          "x_generator": {
            "engine": "Vulnogram 1.0.5"
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "50d0f415-c707-4733-9afc-8f6c0e9b3f82",
        "assignerShortName": "Hitachi",
        "cveId": "CVE-2026-71377",
        "datePublished": "2026-09-08T08:15:00.929Z",
        "dateReserved": "2026-08-06T08:05:05.247Z",
        "dateUpdated": "2026-09-08T12:23:16.192Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2026-71376 (GCVE-0-2026-71376)

    Vulnerability from cvelistv5 – Published: 2026-09-08 08:02 – Updated: 2026-09-08 12:25
    VLAI
    Title
    OS Command Injection Vulnerability in Cosminexus Component Container
    Summary
    OS command injection vulnerability in Cosminexus Component Container. This issue affects Cosminexus Component Container: from 11-70-01 before 11-70-03, from 11-60 before 11-60-03, from 11-50 through 11-50-03, from 11-40 through 11-40-03, from 11-30 through 11-30-08, from 11-20 before 11-20-10, from 11-10 through 11-10-11, from 11-00 before 11-00-13, from 09-87 before 09-87-10, from 09-80 before 09-80-05, from 09-70 before 09-70-28, from 09-50 through 09-50-22, and from 09-00 through 09-00-18.
    SSVC
    Exploitation: none Automatable: yes Technical Impact: total
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2026-09-08 12:25 UTC
    CWE
    • CWE-78 - Improper neutralization of special elements used in an OS command ('OS command injection')
    References
    Impacted products
    Vendor Product Version
    Hitachi Cosminexus Component Container Affected: 11-70-01 , < 11-70-03 (custom)
    Affected: 11-60 , < 11-60-03 (custom)
    Affected: 11-50 , ≤ 11-50-03 (custom)
    Affected: 11-40 , ≤ 11-40-03 (custom)
    Affected: 11-30 , ≤ 11-30-08 (custom)
    Affected: 11-20 , < 11-20-10 (custom)
    Affected: 11-10 , ≤ 11-10-11 (custom)
    Affected: 11-00 , < 11-00-13 (custom)
    Affected: 09-87 , < 09-87-10 (custom)
    Affected: 09-80 , < 09-80-05 (custom)
    Affected: 09-70 , < 09-70-28 (custom)
    Affected: 09-50 , ≤ 09-50-22 (custom)
    Affected: 09-00 , ≤ 09-00-18 (custom)
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2026-71376",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "yes"
                      },
                      {
                        "Technical Impact": "total"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2026-09-08T12:25:14.939516Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2026-09-08T12:25:25.331Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "defaultStatus": "unaffected",
              "platforms": [
                "Windows",
                "Linux",
                "AIX"
              ],
              "product": "Cosminexus Component Container",
              "vendor": "Hitachi",
              "versions": [
                {
                  "changes": [
                    {
                      "at": "11-70-03",
                      "status": "unaffected"
                    }
                  ],
                  "lessThan": "11-70-03",
                  "status": "affected",
                  "version": "11-70-01",
                  "versionType": "custom"
                },
                {
                  "changes": [
                    {
                      "at": "11-60-03",
                      "status": "unaffected"
                    }
                  ],
                  "lessThan": "11-60-03",
                  "status": "affected",
                  "version": "11-60",
                  "versionType": "custom"
                },
                {
                  "lessThanOrEqual": "11-50-03",
                  "status": "affected",
                  "version": "11-50",
                  "versionType": "custom"
                },
                {
                  "lessThanOrEqual": "11-40-03",
                  "status": "affected",
                  "version": "11-40",
                  "versionType": "custom"
                },
                {
                  "lessThanOrEqual": "11-30-08",
                  "status": "affected",
                  "version": "11-30",
                  "versionType": "custom"
                },
                {
                  "changes": [
                    {
                      "at": "11-20-10",
                      "status": "unaffected"
                    }
                  ],
                  "lessThan": "11-20-10",
                  "status": "affected",
                  "version": "11-20",
                  "versionType": "custom"
                },
                {
                  "lessThanOrEqual": "11-10-11",
                  "status": "affected",
                  "version": "11-10",
                  "versionType": "custom"
                },
                {
                  "changes": [
                    {
                      "at": "11-00-13",
                      "status": "unaffected"
                    }
                  ],
                  "lessThan": "11-00-13",
                  "status": "affected",
                  "version": "11-00",
                  "versionType": "custom"
                },
                {
                  "changes": [
                    {
                      "at": "09-87-10",
                      "status": "unaffected"
                    }
                  ],
                  "lessThan": "09-87-10",
                  "status": "affected",
                  "version": "09-87",
                  "versionType": "custom"
                },
                {
                  "changes": [
                    {
                      "at": "09-80-05",
                      "status": "unaffected"
                    }
                  ],
                  "lessThan": "09-80-05",
                  "status": "affected",
                  "version": "09-80",
                  "versionType": "custom"
                },
                {
                  "changes": [
                    {
                      "at": "09-70-28",
                      "status": "unaffected"
                    }
                  ],
                  "lessThan": "09-70-28",
                  "status": "affected",
                  "version": "09-70",
                  "versionType": "custom"
                },
                {
                  "lessThanOrEqual": "09-50-22",
                  "status": "affected",
                  "version": "09-50",
                  "versionType": "custom"
                },
                {
                  "lessThanOrEqual": "09-00-18",
                  "status": "affected",
                  "version": "09-00",
                  "versionType": "custom"
                }
              ]
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "OS command injection vulnerability in Cosminexus Component Container.\u003cp\u003eThis issue affects Cosminexus Component Container: from 11-70-01 before 11-70-03, from 11-60 before 11-60-03, from 11-50 through 11-50-03, from 11-40 through 11-40-03, from 11-30 through 11-30-08, from 11-20 before 11-20-10, from 11-10 through 11-10-11, from 11-00 before 11-00-13, from 09-87 before 09-87-10, from 09-80 before 09-80-05, from 09-70 before 09-70-28, from 09-50 through 09-50-22, and from 09-00 through 09-00-18.\u003c/p\u003e"
                }
              ],
              "value": "OS command injection vulnerability in Cosminexus Component Container.\n\nThis issue affects Cosminexus Component Container: from 11-70-01 before 11-70-03, from 11-60 before 11-60-03, from 11-50 through 11-50-03, from 11-40 through 11-40-03, from 11-30 through 11-30-08, from 11-20 before 11-20-10, from 11-10 through 11-10-11, from 11-00 before 11-00-13, from 09-87 before 09-87-10, from 09-80 before 09-80-05, from 09-70 before 09-70-28, from 09-50 through 09-50-22, and from 09-00 through 09-00-18."
            }
          ],
          "impacts": [
            {
              "capecId": "CAPEC-88",
              "descriptions": [
                {
                  "lang": "en",
                  "value": "CAPEC-88 OS Command Injection"
                }
              ]
            }
          ],
          "metrics": [
            {
              "cvssV3_1": {
                "attackComplexity": "LOW",
                "attackVector": "NETWORK",
                "availabilityImpact": "HIGH",
                "baseScore": 9.8,
                "baseSeverity": "CRITICAL",
                "confidentialityImpact": "HIGH",
                "integrityImpact": "HIGH",
                "privilegesRequired": "NONE",
                "scope": "UNCHANGED",
                "userInteraction": "NONE",
                "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
                "version": "3.1"
              },
              "format": "CVSS",
              "scenarios": [
                {
                  "lang": "en",
                  "value": "GENERAL"
                }
              ]
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-78",
                  "description": "CWE-78 Improper neutralization of special elements used in an OS command (\u0027OS command injection\u0027)",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-09-08T08:02:13.158Z",
            "orgId": "50d0f415-c707-4733-9afc-8f6c0e9b3f82",
            "shortName": "Hitachi"
          },
          "references": [
            {
              "tags": [
                "vendor-advisory"
              ],
              "url": "https://www.hitachi.com/products/it/software/security/info/vuls/hitachi-sec-2026-132/index.html"
            }
          ],
          "source": {
            "advisory": "hitachi-sec-2026-132",
            "discovery": "UNKNOWN"
          },
          "title": "OS Command Injection Vulnerability in Cosminexus Component Container",
          "x_generator": {
            "engine": "Vulnogram 1.0.5"
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "50d0f415-c707-4733-9afc-8f6c0e9b3f82",
        "assignerShortName": "Hitachi",
        "cveId": "CVE-2026-71376",
        "datePublished": "2026-09-08T08:02:13.158Z",
        "dateReserved": "2026-08-06T08:05:05.247Z",
        "dateUpdated": "2026-09-08T12:25:25.331Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2026-71375 (GCVE-0-2026-71375)

    Vulnerability from cvelistv5 – Published: 2026-09-08 07:56 – Updated: 2026-09-08 12:25
    VLAI
    Title
    XXE Vulnerability in Cosminexus Component Container
    Summary
    Improper restriction of XML external entity reference vulnerability in Cosminexus Component Container. This issue affects Cosminexus Component Container: from 11-70-01 before 11-70-03, from 11-60 before 11-60-03, from 11-50 through 11-50-03, from 11-40 through 11-40-03, from 11-30 through 11-30-08, from 11-20 before 11-20-10, from 11-10 through 11-10-11, from 11-00 before 11-00-13, from 09-87 before 09-87-10, from 09-80 before 09-80-05, from 09-70 before 09-70-28, from 09-50 through 09-50-22, and from 09-00 through 09-00-18.
    SSVC
    Exploitation: none Automatable: no Technical Impact: partial
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2026-09-08 12:25 UTC
    CWE
    • CWE-611 - Improper restriction of XML external entity reference
    References
    Impacted products
    Vendor Product Version
    Hitachi Cosminexus Component Container Affected: 11-70-01 , < 11-70-03 (custom)
    Affected: 11-60 , < 11-60-03 (custom)
    Affected: 11-50 , ≤ 11-50-03 (custom)
    Affected: 11-40 , ≤ 11-40-03 (custom)
    Affected: 11-30 , ≤ 11-30-08 (custom)
    Affected: 11-20 , < 11-20-10 (custom)
    Affected: 11-10 , ≤ 11-10-11 (custom)
    Affected: 11-00 , < 11-00-13 (custom)
    Affected: 09-87 , < 09-87-10 (custom)
    Affected: 09-80 , < 09-80-05 (custom)
    Affected: 09-70 , < 09-70-28 (custom)
    Affected: 09-50 , ≤ 09-50-22 (custom)
    Affected: 09-00 , ≤ 09-00-18 (custom)
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2026-71375",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "partial"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2026-09-08T12:25:41.232196Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2026-09-08T12:25:49.908Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "defaultStatus": "unaffected",
              "platforms": [
                "Windows",
                "Linux",
                "AIX"
              ],
              "product": "Cosminexus Component Container",
              "vendor": "Hitachi",
              "versions": [
                {
                  "changes": [
                    {
                      "at": "11-70-03",
                      "status": "unaffected"
                    }
                  ],
                  "lessThan": "11-70-03",
                  "status": "affected",
                  "version": "11-70-01",
                  "versionType": "custom"
                },
                {
                  "changes": [
                    {
                      "at": "11-60-03",
                      "status": "unaffected"
                    }
                  ],
                  "lessThan": "11-60-03",
                  "status": "affected",
                  "version": "11-60",
                  "versionType": "custom"
                },
                {
                  "lessThanOrEqual": "11-50-03",
                  "status": "affected",
                  "version": "11-50",
                  "versionType": "custom"
                },
                {
                  "lessThanOrEqual": "11-40-03",
                  "status": "affected",
                  "version": "11-40",
                  "versionType": "custom"
                },
                {
                  "lessThanOrEqual": "11-30-08",
                  "status": "affected",
                  "version": "11-30",
                  "versionType": "custom"
                },
                {
                  "changes": [
                    {
                      "at": "11-20-10",
                      "status": "unaffected"
                    }
                  ],
                  "lessThan": "11-20-10",
                  "status": "affected",
                  "version": "11-20",
                  "versionType": "custom"
                },
                {
                  "lessThanOrEqual": "11-10-11",
                  "status": "affected",
                  "version": "11-10",
                  "versionType": "custom"
                },
                {
                  "changes": [
                    {
                      "at": "11-00-13",
                      "status": "unaffected"
                    }
                  ],
                  "lessThan": "11-00-13",
                  "status": "affected",
                  "version": "11-00",
                  "versionType": "custom"
                },
                {
                  "changes": [
                    {
                      "at": "09-87-10",
                      "status": "unaffected"
                    }
                  ],
                  "lessThan": "09-87-10",
                  "status": "affected",
                  "version": "09-87",
                  "versionType": "custom"
                },
                {
                  "changes": [
                    {
                      "at": "09-80-05",
                      "status": "unaffected"
                    }
                  ],
                  "lessThan": "09-80-05",
                  "status": "affected",
                  "version": "09-80",
                  "versionType": "custom"
                },
                {
                  "changes": [
                    {
                      "at": "09-70-28",
                      "status": "unaffected"
                    }
                  ],
                  "lessThan": "09-70-28",
                  "status": "affected",
                  "version": "09-70",
                  "versionType": "custom"
                },
                {
                  "lessThanOrEqual": "09-50-22",
                  "status": "affected",
                  "version": "09-50",
                  "versionType": "custom"
                },
                {
                  "lessThanOrEqual": "09-00-18",
                  "status": "affected",
                  "version": "09-00",
                  "versionType": "custom"
                }
              ]
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "Improper restriction of XML external entity reference vulnerability in Cosminexus Component Container.\u003cp\u003eThis issue affects Cosminexus Component Container: from 11-70-01 before 11-70-03, from 11-60 before 11-60-03, from 11-50 through 11-50-03, from 11-40 through 11-40-03, from 11-30 through 11-30-08, from 11-20 before 11-20-10, from 11-10 through 11-10-11, from 11-00 before 11-00-13, from 09-87 before 09-87-10, from 09-80 before 09-80-05, from 09-70 before 09-70-28, from 09-50 through 09-50-22, and from 09-00 through 09-00-18.\u003c/p\u003e"
                }
              ],
              "value": "Improper restriction of XML external entity reference vulnerability in Cosminexus Component Container.\n\nThis issue affects Cosminexus Component Container: from 11-70-01 before 11-70-03, from 11-60 before 11-60-03, from 11-50 through 11-50-03, from 11-40 through 11-40-03, from 11-30 through 11-30-08, from 11-20 before 11-20-10, from 11-10 through 11-10-11, from 11-00 before 11-00-13, from 09-87 before 09-87-10, from 09-80 before 09-80-05, from 09-70 before 09-70-28, from 09-50 through 09-50-22, and from 09-00 through 09-00-18."
            }
          ],
          "impacts": [
            {
              "capecId": "CAPEC-221",
              "descriptions": [
                {
                  "lang": "en",
                  "value": "CAPEC-221 Data Serialization External Entities Blowup"
                }
              ]
            }
          ],
          "metrics": [
            {
              "cvssV3_1": {
                "attackComplexity": "HIGH",
                "attackVector": "NETWORK",
                "availabilityImpact": "HIGH",
                "baseScore": 7.4,
                "baseSeverity": "HIGH",
                "confidentialityImpact": "HIGH",
                "integrityImpact": "NONE",
                "privilegesRequired": "NONE",
                "scope": "UNCHANGED",
                "userInteraction": "NONE",
                "vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:H",
                "version": "3.1"
              },
              "format": "CVSS",
              "scenarios": [
                {
                  "lang": "en",
                  "value": "GENERAL"
                }
              ]
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-611",
                  "description": "CWE-611 Improper restriction of XML external entity reference",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-09-08T07:56:36.056Z",
            "orgId": "50d0f415-c707-4733-9afc-8f6c0e9b3f82",
            "shortName": "Hitachi"
          },
          "references": [
            {
              "tags": [
                "vendor-advisory"
              ],
              "url": "https://www.hitachi.com/products/it/software/security/info/vuls/hitachi-sec-2026-131/index.html"
            }
          ],
          "source": {
            "advisory": "hitachi-sec-2026-131",
            "discovery": "UNKNOWN"
          },
          "title": "XXE Vulnerability in Cosminexus Component Container",
          "x_generator": {
            "engine": "Vulnogram 1.0.5"
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "50d0f415-c707-4733-9afc-8f6c0e9b3f82",
        "assignerShortName": "Hitachi",
        "cveId": "CVE-2026-71375",
        "datePublished": "2026-09-08T07:56:36.056Z",
        "dateReserved": "2026-08-06T08:05:05.247Z",
        "dateUpdated": "2026-09-08T12:25:49.908Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2026-71374 (GCVE-0-2026-71374)

    Vulnerability from cvelistv5 – Published: 2026-09-08 07:47 – Updated: 2026-09-08 12:26
    VLAI
    Title
    Deserialization of Untrusted Data Vulnerability in Cosminexus Component Container
    Summary
    Deserialization of untrusted data vulnerability in Cosminexus Component Container. This issue affects Cosminexus Component Container: from 11-70-01 before 11-70-03, from 11-60 before 11-60-03, from 11-50 through 11-50-03, from 11-40 through 11-40-03, from 11-30 through 11-30-08, from 11-20 before 11-20-10, from 11-10 through 11-10-11, from 11-00 before 11-00-13, from 09-87 before 09-87-10, from 09-80 before 09-80-05, from 09-70 before 09-70-28, from 09-50 through 09-50-22, and from 09-00 through 09-00-18.
    SSVC
    Exploitation: none Automatable: yes Technical Impact: total
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2026-09-08 12:26 UTC
    CWE
    • CWE-502 - Deserialization of untrusted data
    References
    Impacted products
    Vendor Product Version
    Hitachi Cosminexus Component Container Affected: 11-70-01 , < 11-70-03 (custom)
    Affected: 11-60 , < 11-60-03 (custom)
    Affected: 11-50 , ≤ 11-50-03 (custom)
    Affected: 11-40 , ≤ 11-40-03 (custom)
    Affected: 11-30 , ≤ 11-30-08 (custom)
    Affected: 11-20 , < 11-20-10 (custom)
    Affected: 11-10 , ≤ 11-10-11 (custom)
    Affected: 11-00 , < 11-00-13 (custom)
    Affected: 09-87 , < 09-87-10 (custom)
    Affected: 09-80 , < 09-80-05 (custom)
    Affected: 09-70 , < 09-70-28 (custom)
    Affected: 09-50 , ≤ 09-50-22 (custom)
    Affected: 09-00 , ≤ 09-00-18 (custom)
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2026-71374",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "yes"
                      },
                      {
                        "Technical Impact": "total"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2026-09-08T12:26:02.914106Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2026-09-08T12:26:23.042Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "defaultStatus": "unaffected",
              "platforms": [
                "Windows",
                "Linux",
                "AIX"
              ],
              "product": "Cosminexus Component Container",
              "vendor": "Hitachi",
              "versions": [
                {
                  "changes": [
                    {
                      "at": "11-70-03",
                      "status": "unaffected"
                    }
                  ],
                  "lessThan": "11-70-03",
                  "status": "affected",
                  "version": "11-70-01",
                  "versionType": "custom"
                },
                {
                  "changes": [
                    {
                      "at": "11-60-03",
                      "status": "unaffected"
                    }
                  ],
                  "lessThan": "11-60-03",
                  "status": "affected",
                  "version": "11-60",
                  "versionType": "custom"
                },
                {
                  "lessThanOrEqual": "11-50-03",
                  "status": "affected",
                  "version": "11-50",
                  "versionType": "custom"
                },
                {
                  "lessThanOrEqual": "11-40-03",
                  "status": "affected",
                  "version": "11-40",
                  "versionType": "custom"
                },
                {
                  "lessThanOrEqual": "11-30-08",
                  "status": "affected",
                  "version": "11-30",
                  "versionType": "custom"
                },
                {
                  "changes": [
                    {
                      "at": "11-20-10",
                      "status": "unaffected"
                    }
                  ],
                  "lessThan": "11-20-10",
                  "status": "affected",
                  "version": "11-20",
                  "versionType": "custom"
                },
                {
                  "lessThanOrEqual": "11-10-11",
                  "status": "affected",
                  "version": "11-10",
                  "versionType": "custom"
                },
                {
                  "changes": [
                    {
                      "at": "11-00-13",
                      "status": "unaffected"
                    }
                  ],
                  "lessThan": "11-00-13",
                  "status": "affected",
                  "version": "11-00",
                  "versionType": "custom"
                },
                {
                  "changes": [
                    {
                      "at": "09-87-10",
                      "status": "unaffected"
                    }
                  ],
                  "lessThan": "09-87-10",
                  "status": "affected",
                  "version": "09-87",
                  "versionType": "custom"
                },
                {
                  "changes": [
                    {
                      "at": "09-80-05",
                      "status": "unaffected"
                    }
                  ],
                  "lessThan": "09-80-05",
                  "status": "affected",
                  "version": "09-80",
                  "versionType": "custom"
                },
                {
                  "changes": [
                    {
                      "at": "09-70-28",
                      "status": "unaffected"
                    }
                  ],
                  "lessThan": "09-70-28",
                  "status": "affected",
                  "version": "09-70",
                  "versionType": "custom"
                },
                {
                  "lessThanOrEqual": "09-50-22",
                  "status": "affected",
                  "version": "09-50",
                  "versionType": "custom"
                },
                {
                  "lessThanOrEqual": "09-00-18",
                  "status": "affected",
                  "version": "09-00",
                  "versionType": "custom"
                }
              ]
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "Deserialization of untrusted data vulnerability in Cosminexus Component Container.\u003cp\u003eThis issue affects Cosminexus Component Container: from 11-70-01 before 11-70-03, from 11-60 before 11-60-03, from 11-50 through 11-50-03, from 11-40 through 11-40-03, from 11-30 through 11-30-08, from 11-20 before 11-20-10, from 11-10 through 11-10-11, from 11-00 before 11-00-13, from 09-87 before 09-87-10, from 09-80 before 09-80-05, from 09-70 before 09-70-28, from 09-50 through 09-50-22, and from 09-00 through 09-00-18.\u003c/p\u003e"
                }
              ],
              "value": "Deserialization of untrusted data vulnerability in Cosminexus Component Container.\n\nThis issue affects Cosminexus Component Container: from 11-70-01 before 11-70-03, from 11-60 before 11-60-03, from 11-50 through 11-50-03, from 11-40 through 11-40-03, from 11-30 through 11-30-08, from 11-20 before 11-20-10, from 11-10 through 11-10-11, from 11-00 before 11-00-13, from 09-87 before 09-87-10, from 09-80 before 09-80-05, from 09-70 before 09-70-28, from 09-50 through 09-50-22, and from 09-00 through 09-00-18."
            }
          ],
          "impacts": [
            {
              "capecId": "CAPEC-586",
              "descriptions": [
                {
                  "lang": "en",
                  "value": "CAPEC-586 Object Injection"
                }
              ]
            }
          ],
          "metrics": [
            {
              "cvssV3_1": {
                "attackComplexity": "LOW",
                "attackVector": "NETWORK",
                "availabilityImpact": "HIGH",
                "baseScore": 9.8,
                "baseSeverity": "CRITICAL",
                "confidentialityImpact": "HIGH",
                "integrityImpact": "HIGH",
                "privilegesRequired": "NONE",
                "scope": "UNCHANGED",
                "userInteraction": "NONE",
                "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
                "version": "3.1"
              },
              "format": "CVSS",
              "scenarios": [
                {
                  "lang": "en",
                  "value": "GENERAL"
                }
              ]
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-502",
                  "description": "CWE-502 Deserialization of untrusted data",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-09-08T07:47:28.648Z",
            "orgId": "50d0f415-c707-4733-9afc-8f6c0e9b3f82",
            "shortName": "Hitachi"
          },
          "references": [
            {
              "tags": [
                "vendor-advisory"
              ],
              "url": "https://www.hitachi.com/products/it/software/security/info/vuls/hitachi-sec-2026-130/index.html"
            }
          ],
          "source": {
            "advisory": "hitachi-sec-2026-130",
            "discovery": "UNKNOWN"
          },
          "title": "Deserialization of Untrusted Data Vulnerability in Cosminexus Component Container",
          "x_generator": {
            "engine": "Vulnogram 1.0.5"
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "50d0f415-c707-4733-9afc-8f6c0e9b3f82",
        "assignerShortName": "Hitachi",
        "cveId": "CVE-2026-71374",
        "datePublished": "2026-09-08T07:47:28.648Z",
        "dateReserved": "2026-08-06T08:05:05.247Z",
        "dateUpdated": "2026-09-08T12:26:23.042Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2023-6814 (GCVE-0-2023-6814)

    Vulnerability from cvelistv5 – Published: 2024-03-12 03:39 – Updated: 2024-08-02 08:42
    VLAI
    Title
    Information Exposure Vulnerability in Cosminexus Component Container
    Summary
    Insertion of Sensitive Information into Log File vulnerability in Hitachi Cosminexus Component Container allows local users to gain sensitive information.This issue affects Cosminexus Component Container: from 11-30 before 11-30-05, from 11-20 before 11-20-07, from 11-10 before 11-10-10, from 11-00 before 11-00-12, All versions of V8 and V9.
    SSVC
    Exploitation: none Automatable: no Technical Impact: partial
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2024-03-12 13:30 UTC
    CWE
    • CWE-532 - Insertion of Sensitive Information into Log File
    References
    Impacted products
    Vendor Product Version
    Hitachi Cosminexus Component Container Affected: 11-30 , < 11-30-05 (custom)
    Affected: 11-20 , < 11-20-07 (custom)
    Affected: 11-10 , < 11-10-10 (custom)
    Affected: 11-00 , < 11-00-12 (custom)
    Affected: 08-00 , ≤ 09-* (custom)
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2023-6814",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "partial"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2024-03-12T13:30:31.864165Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2024-06-28T01:57:04.242Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          },
          {
            "providerMetadata": {
              "dateUpdated": "2024-08-02T08:42:07.404Z",
              "orgId": "af854a3a-2127-422b-91ae-364da2661108",
              "shortName": "CVE"
            },
            "references": [
              {
                "tags": [
                  "vendor-advisory",
                  "x_transferred"
                ],
                "url": "https://www.hitachi.com/products/it/software/security/info/vuls/hitachi-sec-2024-118/index.html"
              }
            ],
            "title": "CVE Program Container"
          }
        ],
        "cna": {
          "affected": [
            {
              "defaultStatus": "unaffected",
              "product": "Cosminexus Component Container",
              "vendor": "Hitachi",
              "versions": [
                {
                  "changes": [
                    {
                      "at": "11-30-05",
                      "status": "unaffected"
                    }
                  ],
                  "lessThan": "11-30-05",
                  "status": "affected",
                  "version": "11-30",
                  "versionType": "custom"
                },
                {
                  "changes": [
                    {
                      "at": "11-20-07",
                      "status": "unaffected"
                    }
                  ],
                  "lessThan": "11-20-07",
                  "status": "affected",
                  "version": "11-20",
                  "versionType": "custom"
                },
                {
                  "changes": [
                    {
                      "at": "11-10-10",
                      "status": "unaffected"
                    }
                  ],
                  "lessThan": "11-10-10",
                  "status": "affected",
                  "version": "11-10",
                  "versionType": "custom"
                },
                {
                  "changes": [
                    {
                      "at": "11-00-12",
                      "status": "unaffected"
                    }
                  ],
                  "lessThan": "11-00-12",
                  "status": "affected",
                  "version": "11-00",
                  "versionType": "custom"
                },
                {
                  "lessThanOrEqual": "09-*",
                  "status": "affected",
                  "version": "08-00",
                  "versionType": "custom"
                }
              ]
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "Insertion of Sensitive Information into Log File vulnerability in Hitachi Cosminexus Component Container allows local users to gain sensitive information.\u003cp\u003eThis issue affects Cosminexus Component Container: from 11-30 before 11-30-05, from 11-20 before 11-20-07, from 11-10 before 11-10-10, from 11-00 before 11-00-12, All versions of V8 and V9.\u003c/p\u003e"
                }
              ],
              "value": "Insertion of Sensitive Information into Log File vulnerability in Hitachi Cosminexus Component Container allows local users to gain sensitive information.This issue affects Cosminexus Component Container: from 11-30 before 11-30-05, from 11-20 before 11-20-07, from 11-10 before 11-10-10, from 11-00 before 11-00-12, All versions of V8 and V9.\n\n"
            }
          ],
          "impacts": [
            {
              "capecId": "CAPEC-114",
              "descriptions": [
                {
                  "lang": "en",
                  "value": "CAPEC-114 Authentication Abuse"
                }
              ]
            }
          ],
          "metrics": [
            {
              "cvssV3_1": {
                "attackComplexity": "HIGH",
                "attackVector": "LOCAL",
                "availabilityImpact": "NONE",
                "baseScore": 5.6,
                "baseSeverity": "MEDIUM",
                "confidentialityImpact": "HIGH",
                "integrityImpact": "NONE",
                "privilegesRequired": "LOW",
                "scope": "CHANGED",
                "userInteraction": "NONE",
                "vectorString": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:N/A:N",
                "version": "3.1"
              },
              "format": "CVSS",
              "scenarios": [
                {
                  "lang": "en",
                  "value": "GENERAL"
                }
              ]
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-532",
                  "description": "CWE-532 Insertion of Sensitive Information into Log File",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2024-04-16T03:10:06.839Z",
            "orgId": "50d0f415-c707-4733-9afc-8f6c0e9b3f82",
            "shortName": "Hitachi"
          },
          "references": [
            {
              "tags": [
                "vendor-advisory"
              ],
              "url": "https://www.hitachi.com/products/it/software/security/info/vuls/hitachi-sec-2024-118/index.html"
            }
          ],
          "source": {
            "advisory": "hitachi-sec-2024-118",
            "discovery": "UNKNOWN"
          },
          "title": "Information Exposure Vulnerability in Cosminexus Component Container",
          "x_generator": {
            "engine": "Vulnogram 0.1.0-dev"
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "50d0f415-c707-4733-9afc-8f6c0e9b3f82",
        "assignerShortName": "Hitachi",
        "cveId": "CVE-2023-6814",
        "datePublished": "2024-03-12T03:39:22.392Z",
        "dateReserved": "2023-12-14T02:26:36.719Z",
        "dateUpdated": "2024-08-02T08:42:07.404Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.1"
    }