Skip to main content
Hitachi Vantara Knowledge

OpenSSL Security Vulnerabilities

Priority: Medium: CVE-2022-4304, CVE-2022-4450, CVE-2022-0778

       High: CVE-2023-0286, CVE-2023-0215,  CVE-2021-3712

     ● Critical:  CVE-2021-3711

Status:  Resolved

 

First Published: 4 November 2023

Advisory Version: 1.0

References:  CVE-2023-0286, CVE-2023-0215, CVE-2022-4450, CVE-2022-4304, CVE-2022-0778, CVE-2021-3712, CVE-2021-3711

Summary

Hitachi Content Platform has been assessed for OpenSSL vulnerabilities indicated by the CVE identifiers in the reference table above. 

Affected Products

Vulnerable Products

 

The following matrix lists Hitachi Vantara products and solutions which have been confirmed to be affected by any of these vulnerabilities. If a Fixed Release Version is accompanied by a future date, the date is the best estimate we can provide based on current information and mitigation testing progress. If no Fixed Release Version is indicated for an affected product, Hitachi Vantara is continuing to evaluate the fix, and will update this advisory as additional information becomes available.

Product Fixed Release Version
Content Product
Hitachi Content Platform Affected.  Addressed in HCP Release 9.6

 

Products Confirmed Not Vulnerable

At the time of this advisory's publication, only products listed in the Vulnerable Products section above are confirmed to be affected by this vulnerability.

Recommended Actions

 

If any of the information presented above remains unclear, please contact the Hitachi Vantara Global Support Center, or your Vantara-authorized service and support provider.

The information contained herein is for informational purposes only. It is not intended as a guaranty or warranty about Hitachi Vantara’s products, including any guaranty or warranty that any product cannot be exploited by third parties. All product warranties and obligations to a customer must be specified in a mutually acceptable and executed contract between the parties.