Skip to content
Signals
NVD · CVE-2026-64604 · In the Linux kernel, the following vulnerability has been resolved: KVM: VMX: Grab vmcs12 on CR8 interception update iff vCPU is in guest mode When updating CR8NVD · CVE-2026-64603 · In the Linux kernel, the following vulnerability has been resolved: platform/x86: intel-hid: Protect ACPI notify handler against recursion Since commit e2ffcda1NVD · CVE-2026-64602 · In the Linux kernel, the following vulnerability has been resolved: iio: adc: spear: Initialize completion before requesting IRQ In the report from Jaeyoung ChuNVD · CVE-2026-64601 · In the Linux kernel, the following vulnerability has been resolved: ALSA: us144mkii: capture_urb_complete: redundant usb_anchor_urb corrupts anchor list on eachCISA KEV · CVE-2026-8037 · Progress LoadMaster Command Injection Vulnerability · Added 2026-08-07 · Due 2026-08-10CISA KEV · CVE-2026-63077 · 9.8 · JetBrains TeamCity Deserialization of Untrusted Data Vulnerability · Added 2026-08-05 · Due 2026-08-08NVD · CVE-2026-64604 · In the Linux kernel, the following vulnerability has been resolved: KVM: VMX: Grab vmcs12 on CR8 interception update iff vCPU is in guest mode When updating CR8NVD · CVE-2026-64603 · In the Linux kernel, the following vulnerability has been resolved: platform/x86: intel-hid: Protect ACPI notify handler against recursion Since commit e2ffcda1NVD · CVE-2026-64602 · In the Linux kernel, the following vulnerability has been resolved: iio: adc: spear: Initialize completion before requesting IRQ In the report from Jaeyoung ChuNVD · CVE-2026-64601 · In the Linux kernel, the following vulnerability has been resolved: ALSA: us144mkii: capture_urb_complete: redundant usb_anchor_urb corrupts anchor list on eachCISA KEV · CVE-2026-8037 · Progress LoadMaster Command Injection Vulnerability · Added 2026-08-07 · Due 2026-08-10CISA KEV · CVE-2026-63077 · 9.8 · JetBrains TeamCity Deserialization of Untrusted Data Vulnerability · Added 2026-08-05 · Due 2026-08-08

Vendors · hitachi

hitachi

· 5 Critical

Total CVEs

205

Critical

5

Products

279

Search All CVEs →

205

Products (279)

device manager17 CVEsvantara pentaho16 CVEsvantara pentaho business analytics server14 CVEsucosminexus service platform13 CVEstuning manager10 CVEsucosminexus application server standard9 CVEsucosminexus application server enterprise9 CVEsucosminexus service architect8 CVEsgroupmax collaboration portal8 CVEsops center analyzer8 CVEsgroupmax collaboration web client7 CVEsinfrastructure analytics advisor7 CVEsreplication manager7 CVEstiered storage manager6 CVEsit operations director6 CVEscompute systems manager6 CVEscosminexus application server6 CVEscosminexus server6 CVEsucosminexus application server5 CVEsucosminexus developer standard5 CVEsvantara pentaho data integration and analytics5 CVEsjob management partner 1\/it desktop management-manager5 CVEsbusiness logic5 CVEsip5000 voip wifi phone5 CVEsucosminexus collaboration portal5 CVEscosminexus collaboration portal5 CVEscosminexus application server standard4 CVEsucosminexus developer4 CVEsjp1\/it desktop management 2-manager4 CVEsstorage plug-in4 CVEsvantara pentaho business intelligence server4 CVEsjp1\/it desktop management 2-operations director4 CVEslinkone4 CVEscosminexus application server enterprise4 CVEseh-view4 CVEsgroupmax world wide web desktop4 CVEsgroupmax world wide web3 CVEstpi server base3 CVEshi ux we23 CVEsucosminexus operator3 CVEsucosminexus developer light3 CVEsglobal link manager3 CVEscosminexus developer standard version 63 CVEsucosminexus client3 CVEsweb page generator3 CVEsweb page generator enterprise3 CVEsucosminexus developer professional3 CVEsjp1\/it desktop management-manager3 CVEsops center viewpoint3 CVEsautomation director3 CVEspentaho business analytics server3 CVEsjp1\/netm\/dm client3 CVEsjp1 file transmission server3 CVEsjp1\/netm\/dm manager3 CVEsgr30003 CVEsops center common services3 CVEscosminexus developer3 CVEscosminexus developer light version 63 CVEsjp1-cm2-network node manager 2503 CVEsvirtual storage one block3 CVEsgr40003 CVEscosminexus developer professional version 63 CVEsvsp g370 firmware2 CVEsvsp g7002 CVEsvsp g700 firmware2 CVEsvsp g9002 CVEsvsp g900 firmware2 CVEsweb server2 CVEscosminexus client2 CVEsvsp g150 firmware2 CVEscm2-network node manager2 CVEsgr20002 CVEsjp1\/performance management-manager web option2 CVEshitachi directory server 22 CVEscosminexus studio2 CVEsjp1 integrated management service support2 CVEsjp1 p-1b41-94612 CVEsjp1 p-1b41-94712 CVEsjp1 p-1j41-94712 CVEsgroupmax groupware server2 CVEselectronic form workflow2 CVEsops center api configuration manager2 CVEsjob management partner 1\/it desktop management 2-manager2 CVEsjob management partner 1\/remote control agent2 CVEscosminexus enterprise2 CVEsjob management partner 1\/software distribution client2 CVEsraid manager storage replication adapter2 CVEsjob management partner 1\/software distribution manager2 CVEsjp1-cm2-network node manager2 CVEsjp1-hicommand device manager2 CVEsjp1-hicommand global link availability manager2 CVEsjp1-hicommand replication monitor2 CVEsjp1-hicommand tiered storage manager2 CVEselectronic form workflow - standard set2 CVEselectronic form workflow -professional library set2 CVEshc-ip9100hd2 CVEsucosminexus erp integrator2 CVEshc-ip9100hd firmware2 CVEsvsp e10902 CVEsvsp e1090 firmware2 CVEsvsp e1090h2 CVEsvsp e1090h firmware2 CVEsvsp e3902 CVEsvsp e390 firmware2 CVEsvsp e390h2 CVEsvsp e390h firmware2 CVEsvsp e5902 CVEsvsp e590 firmware2 CVEsvsp e590h2 CVEsvsp e590h firmware2 CVEsvsp e7902 CVEsvsp e790 firmware2 CVEsvsp e790h2 CVEsvsp e790h firmware2 CVEsvsp e9902 CVEsvsp e990 firmware2 CVEsvsp f3502 CVEsvsp f350 firmware2 CVEsvsp f3702 CVEsvsp f370 firmware2 CVEsvsp f7002 CVEsvsp f700 firmware2 CVEsvsp f9002 CVEsvsp f900 firmware2 CVEsvsp g1302 CVEsvsp g130 firmware2 CVEsvsp g1502 CVEsconfiguration manager2 CVEsvsp g3502 CVEsvsp g350 firmware2 CVEsvsp g3702 CVEstpbroker developer1 CVEstpbroker object transaction monitor1 CVEstpi link1 CVEstpi net library1 CVEsucosminexus\/opentp1 web web front-endset1 CVEsucosminexus application server smart edition1 CVEsucosminexus collaboration1 CVEsucosminexus content manager1 CVEsucosminexus eur form service1 CVEsucosminexus opentp1 web front-end set1 CVEsvantara hitachi network attached storage1 CVEsvirtual file platform1 CVEsxfit s1 CVEsxfit s jca1 CVEsxfit s zengin1 CVEsxfit s zgin1 CVEsalaxala1 CVEsxp w1 CVEsapplication server v10 manual1 CVEscm2-network node manager 2501 CVEscobol2002 net client suite1 CVEscobol2002 net developer1 CVEscobol2002 net server suite1 CVEscobol gui option1 CVEscobol gui option server1 CVEscommand suite1 CVEscommunity plugin framework1 CVEscontent platform anywhere1 CVEscosminexus\/opentp1 web web front-endset1 CVEscosminexus agent1 CVEscosminexus application server version 51 CVEscosminexus component container1 CVEscosminexus dabroker1 CVEscosminexus developer version 51 CVEscosminexus erp integrator1 CVEscosminexus library standard1 CVEscosminexus library web1 CVEscosminexus opentp1 web front-end set1 CVEscosminexus portal framework1 CVEscosminexus server - enterprise edition1 CVEscosminexus server - standard edition1 CVEscosminexus server - standard edition version 41 CVEscosminexus server - web edition1 CVEscosminexus server - web edition version 41 CVEscosminexus tpbroker1 CVEsdabroker1 CVEsdeveloper\'s kit for java1 CVEselectronic form workflow-developer client set1 CVEselectronic form workflow-developer set1 CVEselectronic form workflow-professional library set1 CVEselectronic form workflow-professional set1 CVEselectronic form workflow-standard set1 CVEselectronic form workflow set1 CVEseur form client1 CVEseur form service1 CVEseur print manager1 CVEseur print service1 CVEseur print service for ilf1 CVEseur professional1 CVEseur viewer1 CVEsgroupmax address server1 CVEsgroupmax collaboration1 CVEsgroupmax integrated desktop1 CVEsgroupmax mail1 CVEsgroupmax mail - security option1 CVEsgroupmax mail server1 CVEsgroupmax mail smtp1 CVEsgroupmax mobile option1 CVEsgroupmax scheduler server set1 CVEsgroupmax server set1 CVEsgroupmax web workflow sdk set for active server pages1 CVEsgroupmax workflow to development kit for active server pages1 CVEsgroupmax world wide web desktop scheduler1 CVEsgroupmax world wide web scheduler1 CVEsgs40001 CVEshi-ux\/we21 CVEshibun advanced edition server1 CVEshirdb datareplicator1 CVEshirdb parallel server1 CVEshirdb server1 CVEshirdb server with additional function1 CVEshirdb single server1 CVEshirdb single server workgroup edition1 CVEshirdb structured data access facility1 CVEshirdb workgroup server1 CVEshitachi web server1 CVEshitsenser31 CVEshitsenser data mart server1 CVEsibm xl c\/c\+\+ v7 for aix \& hitachi developer\'s kit for java1 CVEsibm xl c\/c\+\+ v8 for aix \& hitachi developer\'s kit for java1 CVEsid bravura security fabric1 CVEsit operations analyzer1 CVEsjob management partner 1\/automatic job management system 2-view1 CVEsjob management partner 1\/integrated management-view1 CVEsjob management partner 1\/integrated manager-console view1 CVEsjob management partner 1\/integrated manager-view1 CVEsjob management partner 1\/performance management\/snmp system observer1 CVEsjob management partner 1\/snmp system observer1 CVEsjp1-cm2-hierarchical viewer1 CVEsjp1-cm2-network node manager starter1 CVEsjp1-cm2-network node manager starter 2501 CVEsjp1-hicommand tuning manager1 CVEsjp1-netm-dm manager1 CVEsjp1\/ serverconductor \/ deployment manager1 CVEsjp1\/automatic job management system 2-view1 CVEsjp1\/automatic operation1 CVEsjp1\/cm2\/network node manager1 CVEsjp1\/cm2\/snmp system observer1 CVEsjp1\/integrated management-view1 CVEsjp1\/integrated manager-console view1 CVEsjp1\/integrated manager-view1 CVEsjp1\/netdm\/dm client1 CVEsjp1\/netdm\/dm client-remote control feature1 CVEsjp1\/netdm\/dm manager1 CVEsjp1\/netm\/dm client-remote control feature1 CVEsjp1\/netm\/remote control agent1 CVEsjp1\/netm\/remote control feature1 CVEsjp1\/performance management1 CVEsjp1\/performance management\/snmp system observer1 CVEsjp1\/remote control agent1 CVEsjp1\/remote control feature1 CVEsjp1\/server system observer1 CVEsjp1\/serverconductor\/deploymentmanager1 CVEsjp1 cm2 network node manager1 CVEsjpi automatic job management system 21 CVEsjpi hibun advanced edition server1 CVEsjpi netsight ii port discovery advance1 CVEsjpi netsight ii port discovery standard1 CVEsjpi performance management1 CVEsjpi pfm snmp system observer1 CVEsjpi security integrated manager1 CVEsjpi server conductor blade server manager1 CVEsjpi server conductor server manager1 CVEsjpi server system observer - report feature1 CVEsops center administrator1 CVEsops center automator1 CVEsosas\/ft\/w1 CVEspentaho data integration and analytics1 CVEspki runtime library1 CVEsprocessing kit for xml1 CVEsserverconductor\/deploymentmanager1 CVEsserverconductor \/ deployment manager1 CVEssewb3 mi-platform1 CVEssewb3 platform1 CVEssystem management unit1 CVEssystem management unit firmware1 CVEstp1 net osi-tp-extended1 CVEstpbroker1 CVEs

Recent Vulnerabilities

View all 205
CVE-2026-2255MEDIUM 4.3

Hitachi Vantara Pentaho Data Integration & Analytics versions before 10.2.0.6 and 11.0.0.0, including 9.3.x and 8.3.x, expose Hadoop cluster credentials in plain text through the Cluster Test API. Although the user should not see those explicitly, the defect is mitigated by the fact the user can already leverage those credentials to submit jobs under the same account through the backend API.

CVE-2026-2254MEDIUM 6.3

Hitachi Vantara Pentaho Data Integration & Analytics versions before 10.2.0.6 and 11.0.0.0, including 9.3.x and 8.3.x, does not apply ACLs on certain API endpoints related to platform mail notfications.

CVE-2026-2253HIGH 7.7

Hitachi Vantara Pentaho Data Integration & Analytics versions before 10.2.0.7 and 11.0.0.0, including 9.3.x and 8.3.x, does not prevent certain XML parsers from resolving external entities.

CVE-2025-2514MEDIUM 5.3

Improper restriction of excessive authentication attempts vulnerability in Hitachi Virtual Storage Platform G130, G150, G350, G370, G700, G900, F350, F370, F700, F900, Hitachi Virtual Storage Platform E390, E590, E790, E990, E1090, E390H, E590H, E790H, E1090H, Hitachi Virtual Storage Platform One Block 23, One Block 24, One Block 26, One Block 28. This issue affects Hitachi Virtual Storage Platform G130, G150, G350, G370, G700, G900, F350, F370, F700, F900, Hitachi Virtual Storage Platform E390, E590, E790, E990, E1090, E390H, E590H, E790H, E1090H, Hitachi Virtual Storage Platform One Block 23, One Block 24, One Block 26, One Block 28  : before DKCMAIN Ver 88-08-16-xx/00, GUM Ver. 88-08-20/00, before DKCMAIN Ver 93-07-26-xx/00, GUM Ver. 93-07-26/00, before DKCMAIN Ver A3-04-02-xx/00, EMS Ver. A3-04-02/00, before DKCMAIN Ver A3-03-41-xx/00, EMS Ver. A3-03-41/00, before DKCMAIN Ver A3-03-03-xx/00, EMS Ver. A3-03-02/00.

CVE-2025-1978HIGH 8.3

Remote Code Execution Vulnerability in Hitachi Storage Navigator and the maintenance console in Hitachi Virtual Storage Platform G130, G150, G350, G370, G700, G900, F350, F370, F700, F900, Hitachi Virtual Storage Platform E390, E590, E790, E990, E1090, E390H, E590H, E790H, E1090H, Hitachi Virtual Storage Platform One Block 23, One Block 24, One Block 26, One Block 28. This issue affects Virtual Storage Platform G130, G150, G350, G370, G700, G900, F350, F370, F700, F900, Hitachi Virtual Storage Platform E390, E590, E790, E990, E1090, E390H, E590H, E790H, E1090H, Hitachi Virtual Storage Platform One Block 23, One Block 24, One Block 26, One Block 28  : before DKCMAIN Ver. 88-08-16-xx/00, SVP Ver. 88-08-18-xx/00, before DKCMAIN Ver. 93-07-26-xx/00, SVP Ver. 93-07-26-xx/00, before DKCMAIN Ver. A3-04-02-xx/00, MPC Ver. A3-04-02-xx/00, before DKCMAIN Ver. A3-03-41-xx/00, MPC Ver. A3-03-41-xx/00, before DKCMAIN Ver. A3-03-03-xx/00, MPC Ver. A3-03-03-xx/00.

CVE-2025-9661HIGH 8.1

OS command injection vulneravility in the management gui (maintenance utility) of Hitachi Virtual Storage Platform One Block 23, 24, 26 and 28. This issue affects Hitachi Virtual Storage Platform One Block 23/24/26/28: before DKCMAIN A3-04-21-40/00, ESM A3-04-21/00.

CVE-2025-65116MEDIUM 5.5

Buffer Overflow Vulnerability in JP1/IT Desktop Management 2 - Manager on Windows, JP1/IT Desktop Management 2 - Operations Director on Windows, Job Management Partner 1/IT Desktop Management 2 - Manager on Windows, JP1/IT Desktop Management - Manager on Windows, Job Management Partner 1/IT Desktop Management - Manager on Windows, JP1/NETM/DM Manager on Windows, JP1/NETM/DM Client on Windows, Job Management Partner 1/Software Distribution Manager on Windows, Job Management Partner 1/Software Distribution Client on Windows.This issue affects JP1/IT Desktop Management 2 - Manager: from 13-50 before 13-50-02, from 13-11 before 13-11-04, from 13-10 before 13-10-07, from 13-01 before 13-01-07, from 13-00 before 13-00-05, from 12-60 before 12-60-12, from 10-50 through 12-50-11; JP1/IT Desktop Management 2 - Operations Director: from 13-50 before 13-50-02, from 13-11 before 13-11-04, from 13-10 before 13-10-07, from 13-01 before 13-01-07, from 13-00 before 13-00-05, from 12-60 before 12-60-12, from 10-50 through 12-50-11; Job Management Partner 1/IT Desktop Management 2 - Manager: from 10-50 through 10-50-11; JP1/IT Desktop Management - Manager: from 09-50 through 10-10-16; Job Management Partner 1/IT Desktop Management - Manager: from 09-50 through 10-10-16; JP1/NETM/DM Manager: from 09-00 through 10-20-02; JP1/NETM/DM Client: from 09-00 through 10-20-02; Job Management Partner 1/Software Distribution Manager: from 09-00 through 09-51-13; Job Management Partner 1/Software Distribution Client: from 09-00 through 09-51-13.

CVE-2025-65115HIGH 8.8

Remote Code Execution Vulnerability in JP1/IT Desktop Management 2 - Manager on Windows, JP1/IT Desktop Management 2 - Operations Director on Windows, Job Management Partner 1/IT Desktop Management 2 - Manager on Windows, JP1/IT Desktop Management - Manager on Windows, Job Management Partner 1/IT Desktop Management - Manager on Windows, JP1/NETM/DM Manager on Windows, JP1/NETM/DM Client on Windows, Job Management Partner 1/Software Distribution Manager on Windows, Job Management Partner 1/Software Distribution Client on Windows.This issue affects JP1/IT Desktop Management 2 - Manager: from 13-50 before 13-50-02, from 13-11 before 13-11-04, from 13-10 before 13-10-07, from 13-01 before 13-01-07, from 13-00 before 13-00-05, from 12-60 before 12-60-12, from 10-50 through 12-50-11; JP1/IT Desktop Management 2 - Operations Director: from 13-50 before 13-50-02, from 13-11 before 13-11-04, from 13-10 before 13-10-07, from 13-01 before 13-01-07, from 13-00 before 13-00-05, from 12-60 before 12-60-12, from 10-50 through 12-50-11; Job Management Partner 1/IT Desktop Management 2 - Manager: from 10-50 through 10-50-11; JP1/IT Desktop Management - Manager: from 09-50 through 10-10-16; Job Management Partner 1/IT Desktop Management - Manager: from 09-50 through 10-10-16; JP1/NETM/DM Manager: from 09-00 through 10-20-02; JP1/NETM/DM Client: from 09-00 through 10-20-02; Job Management Partner 1/Software Distribution Manager: from 09-00 through 09-51-13; Job Management Partner 1/Software Distribution Client: from 09-00 through 09-51-13.

CVE-2025-11158CRITICAL 9.1

Hitachi Vantara Pentaho Data Integration & Analytics versions before 10.2.0.6, including 9.3.x and 8.3.x, do not restrict Groovy scripts in new PRPT reports published by users, allowing insertion of arbitrary scripts and leading to a RCE.

CVE-2025-0976MEDIUM 4.7

Information Exposure Vulnerability in Hitachi Ops Center API Configuration Manager, Hitachi Configuration Manager.This issue affects Hitachi Ops Center API Configuration Manager: from 10.0.0-00 before 11.0.4-00; Hitachi Configuration Manager: from 8.6.1-00 before 11.0.5-00.

CVE-2025-5781MEDIUM 5.2

Information Exposure Vulnerability in Hitachi Ops Center API Configuration Manager, Hitachi Configuration Manager, Hitachi Device Manager allows Session Hijacking.This issue affects Hitachi Ops Center API Configuration Manager: from 10.0.0-00 before 11.0.5-00; Hitachi Configuration Manager: from 8.5.1-00 before 11.0.5-00; Hitachi Device Manager: from 8.4.1-00 before 8.6.5-00.

CVE-2024-7125HIGH 7.8

Authentication Bypass vulnerability in Hitachi Ops Center Common Services.This issue affects Hitachi Ops Center Common Services: from 10.9.3-00 before 11.0.2-01.

CVE-2024-5828HIGH 8.6

Expression Language Injection vulnerability in Hitachi Tuning Manager on Windows, Linux, Solaris allows Code Injection.This issue affects Hitachi Tuning Manager: before 8.8.7-00.

CVE-2024-2819MEDIUM 5.1

Incorrect Default Permissions, Improper Preservation of Permissions vulnerability in Hitachi Ops Center Common Services allows File Manipulation.This issue affects Hitachi Ops Center Common Services: before 11.0.2-00.

CVE-2024-28984HIGH 8.8

Hitachi Vantara Pentaho Business Analytics Server prior to versions 10.1.0.0 and 9.3.0.7, including 8.3.x allow a malicious URL to inject content into the Analyzer plugin interface.

CVE-2024-28983HIGH 8.8

Hitachi Vantara Pentaho Business Analytics Server prior to versions 10.1.0.0 and 9.3.0.7, including 8.3.x allow a malicious URL to inject content into the Analyzer plugin interface.

CVE-2024-28982HIGH 7.1

Hitachi Vantara Pentaho Business Analytics Server versions before 10.1.0.0 and 9.3.0.7, including 8.3.x do not correctly protect the ACL service endpoint of the Pentaho User Console against XML External Entity Reference.

CVE-2023-5617MEDIUM 5.3

Hitachi Vantara Pentaho Data Integration & Analytics versions before 10.1.0.0 and 9.3.0.6, including 9.5.x and 8.3.x, display the version of Tomcat when a server error is encountered.

CVE-2024-0715HIGH 7.6

Expression Language Injection vulnerability in Hitachi Global Link Manager on Windows allows Code Injection.This issue affects Hitachi Global Link Manager: before 8.8.7-03.

CVE-2024-21840HIGH 7.9

Incorrect Default Permissions vulnerability in Hitachi Storage Plug-in for VMware vCenter allows local users to read and write specific files. This issue affects Hitachi Storage Plug-in for VMware vCenter: from 04.0.0 through 04.9.2.

CVE-2023-6457MEDIUM 6.6

Incorrect Default Permissions vulnerability in Hitachi Tuning Manager on Windows (Hitachi Tuning Manager server component) allows local users to read and write specific files.This issue affects Hitachi Tuning Manager: before 8.8.5-04.

CVE-2023-49107MEDIUM 5.3

Generation of Error Message Containing Sensitive Information vulnerability in Hitachi Device Manager on Windows, Linux (Device Manager Agent modules).This issue affects Hitachi Device Manager: before 8.8.5-04.

CVE-2023-49106MEDIUM 4.6

Missing Password Field Masking vulnerability in Hitachi Device Manager on Windows, Linux (Device Manager Agent component).This issue affects Hitachi Device Manager: before 8.8.5-04.

CVE-2023-3517HIGH 8.5

Hitachi Vantara Pentaho Data Integration & Analytics versions before 9.5.0.1 and 9.3.0.5, including 8.3.x does not restrict JNDI identifiers during the creation of XActions, allowing control of system level data sources.

CVE-2023-6538HIGH 7.6

SMU versions prior to 14.8.7825.01 are susceptible to unintended information disclosure, through URL manipulation. Authenticated users in Storage, Server or combined Server+Storage administrative roles are able to access SMU configuration backup, that would normally be barred to those specific administrative roles.