Back

HIGH

A vulnerability exists in the Lumada APM’s User Asset Group feature due to a flaw in access control mechanism implementation on the “Limited Engineer” role.

Published Jan 12, 2023

Description

A vulnerability exists in the affected versions of Lumada APM’s User Asset Group feature due to a flaw in access control mechanism implementation on the “Limited Engineer” role, granting it access to the embedded Power BI reports feature. An attacker that manages to exploit the vulnerability on a customer’s Lumada APM could access unauthorized information by gaining unauthorized access to any Power BI reports installed by the customer. 

Furthermore, the vulnerability enables an attacker to manipulate asset issue comments on assets, which should not be available to the attacker.

Affected versions * Lumada APM on-premises version 6.0.0.0 - 6.4.0.*

List of CPEs:  * cpe:2.3:a:hitachienergy:lumada_apm:6.0.0.0:*:*:*:*:*:*:* * cpe:2.3:a:hitachienergy:lumada_apm:6.1.0.0:*:*:*:*:*:*:* * cpe:2.3:a:hitachienergy:lumada_apm:6.2.0.0:*:*:*:*:*:*:* * cpe:2.3:a:hitachienergy:lumada_apm:6.3.0.0:*:*:*:*:*:*:* * cpe:2.3:a:hitachienergy:lumada_apm:6.4.0.0:*:*:*:*:*:*:*

Affected products

Remediation

Vendor solution

* For Lumada APM version 6.4.0.* – Update to Lumada APM version 6.4.0.1, or upgrade to Lumada APM version 6.5.0.0 (or newer).

* For Lumada APM versions prior to 6.4.0.0 – Upgrade to Lumada APM version 6.4.0.1 or 6.5.0.0 or newer.

Metrics

References (1)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner Hitachi Energy
Published Jan 12, 2023
Updated Apr 7, 2025
Reserved Jun 21, 2022
CISA Vulnrichment
Updated Apr 7, 2025
NVD
Status Modified
Modified Jun 17, 2026
Red Hat
Severity n/a
Public date n/a