Vulnerabilities (CVE)

Filtered by vendor Hitachienergy
Filtered by product Lumada Asset Performance Management
Angry Yack Logo
Total 1 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2022-2155 1 Hitachienergy 1 Lumada Asset Performance Management 2024-11-21 N/A 5.7 MEDIUM
A vulnerability exists in the affected versions of Lumada APM’s User Asset Group feature due to a flaw in access control mechanism implementation on the “Limited Engineer” role, granting it access to the embedded Power BI reports feature. An attacker that manages to exploit the vulnerability on a customer’s Lumada APM could access unauthorized information by gaining unauthorized access to any Power BI reports installed by the customer.  Furthermore, the vulnerability enables an attacker to man ...

Show More