CVE-2025-5781 Details
Description
Information Exposure Vulnerability in Hitachi Ops Center API Configuration Manager, Hitachi Configuration Manager, Hitachi Device Manager allows Session Hijacking.This issue affects Hitachi Ops Center API Configuration Manager: from 10.0.0-00 before 11.0.5-00; Hitachi Configuration Manager: from 8.5.1-00 before 11.0.5-00; Hitachi Device Manager: from 8.4.1-00 before 8.6.5-00.
A session hijacking vulnerability has been identified in Hitachi Ops Center API Configuration Manager (versions 10.0.0-00 prior to 11.0.5-00), Hitachi Configuration Manager (versions 8.5.1-00 prior to 11.0.5-00), and Hitachi Device Manager (versions 8.4.1-00 prior to 8.6.5-00). This vulnerability allows session tokens to be improperly stored, potentially leading to unauthorized access.
Users of Hitachi Device Manager should upgrade to Hitachi Configuration Manager 11.0.5-00 or later. If the REST API functionality is not needed, it is recommended to uninstall Hitachi Configuration Manager. Users of Hitachi Configuration Manager or Hitachi Ops Center API Configuration Manager should upgrade to version 11.0.5-00.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Feb 26, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://www.hitachi.com/products/it/software/security/info/vuls/hitachi-sec-2026-111/index.html | [email protected] | Vendor Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-532 | Insertion of Sensitive Information into Log File | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| hitachi configuration manager | >= 8.5.1-00 >= 8.5.1-00, < 11.0.5-00 |
CPE
Remediation
| |
| hitachi device manager | >= 8.4.1-00, < 8.6.5-00 |
CPE
Remediation
| |
| hitachi ops center api configuration manager | >= 10.0.0-00, < 11.0.5-00 |
CPE
Remediation
| |
| linux linux kernel | All versions |
CPE
Remediation
| |
| microsoft windows | All versions |
CPE
Remediation
| |
Change History
4 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Feb 27, 2026 | Initial Analysis | [email protected] |
| Feb 25, 2026 | New CVE Received | [email protected] |