PT-2026-103686 · Hitachi · Coding Software Suite
CVSS v3.1
9.8
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Hitachi Coding Software Suite versions prior to 3.3.0
Description
The software contains a flaw involving the use of a hard-coded cryptographic key. Specifically, the JWT (JSON Web Token) signing secret key is hard-coded, which allows an attacker to generate unauthorized Bearer tokens to exploit administrative functions.
Recommendations
Update Hitachi Coding Software Suite to version 3.3.0 or later.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Coding Software Suite