Lucene search

K
cveHitachiCVE-2023-1995
HistoryAug 29, 2023 - 2:15 a.m.

CVE-2023-1995

2023-08-2902:15:07
CWE-778
Hitachi
web.nvd.nist.gov
23
hitachi
hirdb server
logging
vulnerability
security
cve-2023-1995

CVSS3

7.5

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

HIGH

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N

EPSS

0.001

Percentile

28.7%

Insufficient Logging vulnerability in Hitachi HiRDB Server, HiRDB Server With Addtional Function, HiRDB Structured Data Access Facility.This issue affects HiRDB Server: before 09-60-39, before 09-65-23,

before 09-66-17,

before 10-01-10, before 10-03-12, before 10-04-06, before 10-05-06, before 10-06-02; HiRDB Server With Addtional Function: before 09-60-2M, before 09-65-/W

, before 09-66-/Q

; HiRDB Structured Data Access Facility: before 09-60-39, before 10-03-12, before 10-04-06, before 10-06-02.

Affected configurations

Nvd
Node
hitachihirdb_server_with_additional_functionRange09-0009-00-2d
OR
hitachihirdb_server_with_additional_functionRange09-0109-01-\/x
OR
hitachihirdb_server_with_additional_functionRange09-0209-02-2f
OR
hitachihirdb_server_with_additional_functionRange09-0309-03-2a
OR
hitachihirdb_server_with_additional_functionRange09-0409-04-2s
OR
hitachihirdb_server_with_additional_functionRange09-5009-50-2k
OR
hitachihirdb_server_with_additional_functionRange09-6009-60-2k
OR
hitachihirdb_server_with_additional_functionRange09-6509-65-\/v
OR
hitachihirdb_server_with_additional_functionRange09-6609-66-\/p
AND
hphp-uxMatch-
OR
linuxlinux_kernelMatch-
OR
microsoftwindowsMatch-
Node
hitachihirdb_server_with_additional_functionRange09-0009-00-2f
OR
hitachihirdb_server_with_additional_functionRange09-0109-01-\/x
OR
hitachihirdb_server_with_additional_functionRange09-0209-02-2f
OR
hitachihirdb_server_with_additional_functionRange09-0309-03-2e
OR
hitachihirdb_server_with_additional_functionRange09-0409-04-2s
OR
hitachihirdb_server_with_additional_functionRange09-5009-50-2k
OR
hitachihirdb_server_with_additional_functionRange09-6009-60-2l
OR
hitachihirdb_server_with_additional_functionRange09-6509-65-\/v
OR
hitachihirdb_server_with_additional_functionRange09-6609-66-\/p
AND
ibmaixMatch-
Node
hitachihirdb_structured_data_access_facilityRange09-6009-60-37
OR
hitachihirdb_structured_data_access_facilityRange09-6609-66-06
OR
hitachihirdb_structured_data_access_facilityRange10-0110-01-03
OR
hitachihirdb_structured_data_access_facilityRange10-0210-02-12
OR
hitachihirdb_structured_data_access_facilityRange10-0310-03-10
OR
hitachihirdb_structured_data_access_facilityRange10-0410-04-05
OR
hitachihirdb_structured_data_access_facilityRange10-0610-06-01
AND
linuxlinux_kernelMatch-
Node
hitachihirdb_serverRange09-0009-00-30
OR
hitachihirdb_serverRange09-0109-01-24
OR
hitachihirdb_serverRange09-0209-02-32
OR
hitachihirdb_serverRange09-0309-03-27
OR
hitachihirdb_serverRange09-0409-04-31
AND
oraclesolarisMatch-
Node
hitachihirdb_serverRange09-0009-00-32
OR
hitachihirdb_serverRange09-0109-01-24
OR
hitachihirdb_serverRange09-0209-02-32
OR
hitachihirdb_serverRange09-0309-03-31
OR
hitachihirdb_serverRange09-0409-04-45
OR
hitachihirdb_serverRange09-5009-50-37
OR
hitachihirdb_serverRange09-6009-60-38
OR
hitachihirdb_serverRange09-6509-65-22
OR
hitachihirdb_serverRange09-6609-66-16
OR
hitachihirdb_serverRange10-0010-00-09
OR
hitachihirdb_serverRange10-0110-01-09
OR
hitachihirdb_serverRange10-0210-02-12
OR
hitachihirdb_serverRange10-0310-03-11
OR
hitachihirdb_serverRange10-0410-04-04
OR
hitachihirdb_serverRange10-0510-05-05
OR
hitachihirdb_serverRange10-0610-06-01
AND
ibmaixMatch-
Node
hitachihirdb_serverRange09-0009-00-32
OR
hitachihirdb_serverRange09-0109-01-24
OR
hitachihirdb_serverRange09-0209-02-32
OR
hitachihirdb_serverRange09-0309-03-31
OR
hitachihirdb_serverRange09-0409-04-45
OR
hitachihirdb_serverRange09-5009-50-37
OR
hitachihirdb_serverRange09-6009-60-38
OR
hitachihirdb_serverRange09-6509-65-22
OR
hitachihirdb_serverRange09-6609-66-16
OR
hitachihirdb_serverRange10-0010-00-09
OR
hitachihirdb_serverRange10-0110-01-09
OR
hitachihirdb_serverRange10-0210-02-12
OR
hitachihirdb_serverRange10-0310-03-10
OR
hitachihirdb_serverRange10-0410-04-04
OR
hitachihirdb_serverRange10-0510-05-05
OR
hitachihirdb_serverRange10-0610-06-01
AND
microsoftwindowsMatch-
Node
hitachihirdb_serverRange09-0009-00-32
OR
hitachihirdb_serverRange09-0109-01-24
OR
hitachihirdb_serverRange09-0209-02-32
OR
hitachihirdb_serverRange09-0309-03-31
OR
hitachihirdb_serverRange09-0409-04-45
OR
hitachihirdb_serverRange09-5009-50-37
OR
hitachihirdb_serverRange09-6009-60-38
OR
hitachihirdb_serverRange09-6509-65-22
OR
hitachihirdb_serverRange09-6609-66-16
OR
hitachihirdb_serverRange10-0010-00-09
OR
hitachihirdb_serverRange10-0110-01-09
OR
hitachihirdb_serverRange10-0210-02-12
OR
hitachihirdb_serverRange10-0310-03-10
OR
hitachihirdb_serverRange10-0410-04-05
OR
hitachihirdb_serverRange10-0510-05-05
OR
hitachihirdb_serverRange10-0610-06-01
AND
linuxlinux_kernelMatch-
Node
hitachihirdb_serverRange09-0009-00-30
OR
hitachihirdb_serverRange09-0109-01-24
OR
hitachihirdb_serverRange09-0209-02-32
OR
hitachihirdb_serverRange09-0309-03-27
OR
hitachihirdb_serverRange09-0409-04-45
OR
hitachihirdb_serverRange09-5009-50-37
OR
hitachihirdb_serverRange09-6009-60-37
OR
hitachihirdb_serverRange09-6509-65-22
OR
hitachihirdb_serverRange09-6609-66-16
OR
hitachihirdb_serverRange10-0010-00-09
OR
hitachihirdb_serverRange10-0110-01-09
OR
hitachihirdb_serverRange10-0210-02-12
OR
hitachihirdb_serverRange10-0310-03-10
OR
hitachihirdb_serverRange10-0410-04-04
OR
hitachihirdb_serverRange10-0510-05-05
AND
hphp-uxMatch-
VendorProductVersionCPE
hitachihirdb_server_with_additional_function*cpe:2.3:a:hitachi:hirdb_server_with_additional_function:*:*:*:*:*:*:*:*
hphp-ux-cpe:2.3:o:hp:hp-ux:-:*:*:*:*:*:*:*
linuxlinux_kernel-cpe:2.3:o:linux:linux_kernel:-:*:*:*:*:*:*:*
microsoftwindows-cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:*:*
ibmaix-cpe:2.3:o:ibm:aix:-:*:*:*:*:*:*:*
hitachihirdb_structured_data_access_facility*cpe:2.3:a:hitachi:hirdb_structured_data_access_facility:*:*:*:*:*:*:*:*
hitachihirdb_server*cpe:2.3:a:hitachi:hirdb_server:*:*:*:*:*:*:*:*
oraclesolaris-cpe:2.3:o:oracle:solaris:-:*:*:*:*:*:*:*

CNA Affected

[
  {
    "defaultStatus": "unaffected",
    "product": "HiRDB Server",
    "vendor": "Hitachi",
    "versions": [
      {
        "lessThan": "09-60",
        "status": "affected",
        "version": "07-03",
        "versionType": "custom"
      },
      {
        "changes": [
          {
            "at": "09-60-39",
            "status": "unaffected"
          }
        ],
        "lessThan": "09-60-39",
        "status": "affected",
        "version": "09-60",
        "versionType": "custom"
      },
      {
        "changes": [
          {
            "at": "09-65-23",
            "status": "unaffected"
          }
        ],
        "lessThan": "09-65-23",
        "status": "affected",
        "version": "09-65",
        "versionType": "custom"
      },
      {
        "changes": [
          {
            "at": "09-66-17",
            "status": "unaffected"
          }
        ],
        "lessThan": "09-66-17",
        "status": "affected",
        "version": "09-66",
        "versionType": "custom"
      },
      {
        "lessThanOrEqual": "10-00-*",
        "status": "affected",
        "version": "10-00",
        "versionType": "custom"
      },
      {
        "changes": [
          {
            "at": "10-01-10",
            "status": "unaffected"
          }
        ],
        "lessThan": "10-01-10",
        "status": "affected",
        "version": "10-01",
        "versionType": "custom"
      },
      {
        "lessThanOrEqual": "10-02-*",
        "status": "affected",
        "version": "10-02",
        "versionType": "custom"
      },
      {
        "changes": [
          {
            "at": "10-03-12",
            "status": "unaffected"
          }
        ],
        "lessThan": "10-03-12",
        "status": "affected",
        "version": "10-03",
        "versionType": "custom"
      },
      {
        "changes": [
          {
            "at": "10-04-06",
            "status": "unaffected"
          }
        ],
        "lessThan": "10-04-06",
        "status": "affected",
        "version": "10-04",
        "versionType": "custom"
      },
      {
        "changes": [
          {
            "at": "10-05-06",
            "status": "unaffected"
          }
        ],
        "lessThan": "10-05-06",
        "status": "affected",
        "version": "10-05",
        "versionType": "custom"
      },
      {
        "changes": [
          {
            "at": "10-06-02",
            "status": "unaffected"
          }
        ],
        "lessThan": "10-06-02",
        "status": "affected",
        "version": "10-06",
        "versionType": "custom"
      }
    ]
  },
  {
    "defaultStatus": "unaffected",
    "product": "HiRDB Server With Addtional Function",
    "vendor": "Hitachi",
    "versions": [
      {
        "lessThan": "09-60",
        "status": "affected",
        "version": "07-03",
        "versionType": "custom"
      },
      {
        "changes": [
          {
            "at": "09-60-2M",
            "status": "unaffected"
          }
        ],
        "lessThan": "09-60-2M",
        "status": "affected",
        "version": "09-60",
        "versionType": "custom"
      },
      {
        "changes": [
          {
            "at": "09-65-/W",
            "status": "unaffected"
          }
        ],
        "lessThan": "09-65-/W",
        "status": "affected",
        "version": "09-65",
        "versionType": "custom"
      },
      {
        "changes": [
          {
            "at": "09-66-/Q",
            "status": "unaffected"
          }
        ],
        "lessThan": "09-66-/Q",
        "status": "affected",
        "version": "09-66",
        "versionType": "custom"
      }
    ]
  },
  {
    "defaultStatus": "unaffected",
    "product": "HiRDB Structured Data Access Facility",
    "vendor": "Hitachi",
    "versions": [
      {
        "lessThan": "09-60",
        "status": "affected",
        "version": "07-03",
        "versionType": "custom"
      },
      {
        "changes": [
          {
            "at": "09-60-39",
            "status": "unaffected"
          }
        ],
        "lessThan": "09-60-39",
        "status": "affected",
        "version": "09-60",
        "versionType": "custom"
      },
      {
        "lessThanOrEqual": "09-65-*",
        "status": "affected",
        "version": "09-65",
        "versionType": "custom"
      },
      {
        "lessThanOrEqual": "09-66-*",
        "status": "affected",
        "version": "09-66",
        "versionType": "custom"
      },
      {
        "lessThanOrEqual": "10-00-*",
        "status": "affected",
        "version": "10-00",
        "versionType": "custom"
      },
      {
        "lessThanOrEqual": "10-01-*",
        "status": "affected",
        "version": "10-01",
        "versionType": "custom"
      },
      {
        "lessThanOrEqual": "10-02-*",
        "status": "affected",
        "version": "10-02",
        "versionType": "custom"
      },
      {
        "changes": [
          {
            "at": "10-03-12",
            "status": "unaffected"
          }
        ],
        "lessThan": "10-03-12",
        "status": "affected",
        "version": "10-03",
        "versionType": "custom"
      },
      {
        "changes": [
          {
            "at": "10-04-06",
            "status": "unaffected"
          }
        ],
        "lessThan": "10-04-06",
        "status": "affected",
        "version": "10-04",
        "versionType": "custom"
      },
      {
        "lessThanOrEqual": "10-05-*",
        "status": "affected",
        "version": "10-05",
        "versionType": "custom"
      },
      {
        "changes": [
          {
            "at": "10-06-02",
            "status": "unaffected"
          }
        ],
        "lessThan": "10-06-02",
        "status": "affected",
        "version": "10-06",
        "versionType": "custom"
      }
    ]
  }
]

CVSS3

7.5

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

HIGH

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N

EPSS

0.001

Percentile

28.7%

Related for CVE-2023-1995