Hitachi, Ltd. maintains a large and diverse portfolio of enterprise infrastructure, storage, and analytics products spanning device management, business intelligence platforms, middleware, and system tuning solutions—a footprint that reflects its role as a major supplier to large-scale IT deployments. Vulnerabilities affecting the vendor reach a meaningful share of serious severity across this broad product range, concentrating in web-facing and input-processing components where cross-site scripting, improper input validation, and permission misconfigurations recur. The exposure spans flagship products including Device Manager, Vantara Pentaho analytics platforms, UCOSMINEXUS middleware, and Tuning Manager, each representing integration points in enterprise infrastructure that can amplify the impact of underlying flaws. Defenders should prioritize inventory of Hitachi-supplied systems in critical roles and track the vendor's advisories for the infrastructure and analytics layers; live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Hitachi, Ltd. over time
Of all the CVEs published by Hitachi, Ltd. as a CNA, 60.8% affect products that Hitachi, Ltd. develops as a vendor.
Of all the CVEs published that affect products developed by Hitachi, Ltd., 20.7% are self-published by Hitachi, Ltd. as a CNA.
Signals from CVEs in this vendor scope (217 CVEs).
217 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2022-43939CRITICAL Hitachi Vantara Pentaho Business Analytics Server versions before 9.4.0.1 and 9.3.0.2, including 8.3.x contain security restrictions using non-canonical URLs which can be circumven | Apr 3, 2023 | 9.8 | 99 | YES | YES |
CVE-2022-43769HIGH Hitachi Vantara Pentaho Business Analytics Server prior to versions 9.4.0.1 and 9.3.0.2, including 8.3.x allow certain web services to set property values which contain Spring temp | Apr 3, 2023 | 7.2 | 98 | YES | YES |
CVE-2005-0356MEDIUM Multiple TCP implementations with Protection Against Wrapped Sequence Numbers (PAWS) with the timestamps option enabled allow remote attackers to cause a denial of service (connect | May 31, 2005 | 5.0 | 69 | NO | YES |
CVE-2021-31602HIGH An issue was discovered in Hitachi Vantara Pentaho through 9.1 and Pentaho Business Intelligence Server through 7.x. The Security Model has different layers of Access Control. One | Nov 8, 2021 | 7.5 | 64 | NO | YES |
CVE-2022-43938HIGH
Hitachi Vantara Pentaho Business Analytics Server prior to versions 9.4.0.1 and 9.3.0.2, including 8.3.x cannot allow a system administrator to disable scripting capabilities of P | Apr 3, 2023 | 8.8 | 41 | NO | NO |
CVE-2022-43773HIGH
Hitachi Vantara Pentaho Business Analytics Server prior to versions 9.4.0.1 and 9.3.0.2, including 8.3.x is installed with a sample HSQLDB data source configured with stored proce | Apr 3, 2023 | 8.8 | 37 | NO | NO |
CVE-2025-1978CRITICAL Remote Code Execution Vulnerability in Hitachi Storage Navigator and the maintenance console in Hitachi Virtual Storage Platform G130, G150, G350, G370, G700, G900, F350, F370, F70 | May 7, 2026 | 9.8 | 36 | NO | NO |
CVE-2025-9661CRITICAL OS command injection vulneravility in the management gui (maintenance utility) of Hitachi Virtual Storage Platform One Block 23, 24, 26 and 28.
This issue affects Hitachi Virtual | May 7, 2026 | 9.8 | 36 | NO | NO |
CVE-2026-2253HIGH Hitachi Vantara Pentaho Data Integration & Analytics versions before 10.2.0.7 and 11.0.0.0, including 9.3.x and 8.3.x, does not prevent certain XML parsers from resolving external | May 27, 2026 | 7.7 | 33 | NO | NO |
CVE-2025-65115CRITICAL Remote Code Execution Vulnerability in JP1/IT Desktop Management 2 - Manager on Windows, JP1/IT Desktop Management 2 - Operations Director on Windows, Job Management Partner 1/IT D | Apr 7, 2026 | 9.8 | 33 | NO | NO |
Signals from CVEs in this vendor scope (217 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Hitachi, Ltd..
Media articles that mention a CVE ID that affects a product developed by Hitachi, Ltd. — matched by CVE ID, not by vendor name.