Executive brief
Hitachi Cosminexus Component Container, a middleware platform used to manage enterprise applications, contains a command argument injection vulnerability in its operation management agent. An attacker with network access can inject malicious arguments into system commands, leading to remote code execution without authentication. This could allow complete compromise of the server and all applications it hosts.
Technical details
A command argument injection vulnerability exists in the operation management agent of Cosminexus Component Container. The vulnerability is triggered via network-accessible interfaces, requires no authentication or user interaction, and allows attackers to inject arbitrary command arguments. An attacker can achieve code execution with high impact on confidentiality, integrity, and availability (CVSS 9.8). Patches are available: Cosminexus Component Container versions 09-70-28, 09-87-10, 11-20-10, 11-60-03, and 11-70-03 address this issue; affected installations should upgrade immediately.
Affected products
- Hitachi Cosminexus Component Container V11: 11-00-0 through 11-70-02 (multiple branches); V9: 09-00-0 through 09-87-09 (multiple branches)
Timeline
- 2026-09-08: disclosed