Risk: Medium
Vulnerabilities:
1. Some unspecified input passed in input forms isn't properly sanitised before being returned to the user. This can be exploited to execute arbitrary HTML and script code in a user's browser session in context of an affected site.
This can also be exploited to inject arbitrary HTTP headers, which will be included in the response sent to the user.
2. Some unspecified input passed in input forms isn't properly sanitised before being used in a SQL query. This can be exploited to manipulate SQL queries by injecting arbitrary SQL code.
The vulnerabilities has been reported in Hitachi Business Logic - Container versions 01-00 through 02-06 for Windows and versions 01-01 through 02-00 for AIX.