Asset Suite 允许未经身份验证的用户访问 HTTPPublishAdapterTestServlet,该 Servlet 可用于上传配置文件,从而导致信息泄露和完整性被破坏。HTTPPublishAdapterTestServlet 专为测试目的而设计,仅应用于非生产环境。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Hitachi Energy | Asset Suite | 9.6.0 ~ 9.9.0 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-8066 | 9.1 CRITICAL | CVE-2026-8066 |
| CVE-2026-8065 | 9.1 CRITICAL | CVE-2026-8065 |
| CVE-2026-8067 | 6.5 MEDIUM | CVE-2026-8067 |
| CVE-2026-11796 | 5.1 MEDIUM | Asset Suite未授权访问Servlet致拒绝服务漏洞 |
No comments yet