Lucene search

K
cve[email protected]CVE-2023-3440
HistoryOct 03, 2023 - 2:15 a.m.

CVE-2023-3440

2023-10-0302:15:09
CWE-276
web.nvd.nist.gov
43
hitachi
jp1
performance management
windows
cve-2023-3440
vulnerability
nvd
file manipulation
default permissions

8.4 High

CVSS3

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

7.6 High

AI Score

Confidence

High

0.0004 Low

EPSS

Percentile

9.1%

Incorrect Default Permissions vulnerability in Hitachi JP1/Performance Management on Windows allows File Manipulation.This issue affects JP1/Performance Management - Manager: from 09-00 before 12-50-07; JP1/Performance Management - Base: from 09-00 through 10-50-; JP1/Performance Management - Agent Option for Application Server: from 11-00 before 11-50-16; JP1/Performance Management - Agent Option for Enterprise Applications: from 09-00 before 12-00-14; JP1/Performance Management - Agent Option for HiRDB: from 09-00 before 12-00-14; JP1/Performance Management - Agent Option for IBM Lotus Domino: from 10-00 before 11-50-16; JP1/Performance Management - Agent Option for Microsoft® Exchange Server: from 09-00 before  12-00-14; JP1/Performance Management - Agent Option for Microsoft® Internet Information Server: from 09-00 before 12-00-14; JP1/Performance Management - Agent Option for Microsoft® SQL Server: from 09-00 before 12-50-07; JP1/Performance Management - Agent Option for Oracle: from 09-00 before  12-10-08; JP1/Performance Management - Agent Option for Platform: from 09-00 before 12-50-07; JP1/Performance Management - Agent Option for Service Response: from 09-00 before 11-50-16; JP1/Performance Management - Agent Option for Transaction System: from 11-00 before 12-00-14; JP1/Performance Management - Remote Monitor for Microsoft® SQL Server: from 09-00 before 12-50-07; JP1/Performance Management - Remote Monitor for Oracle: from 09-00 before 12-10-08; JP1/Performance Management - Remote Monitor for Platform: from 09-00 before 12-10-08; JP1/Performance Management - Remote Monitor for Virtual Machine: from 10-00 before 12-50-07; JP1/Performance Management - Agent Option for Domino: from 09-00 through 09-00-; JP1/Performance Management - Agent Option for IBM WebSphere Application Server: from 09-00 through 10-00-; JP1/Performance Management - Agent Option for IBM WebSphere MQ: from 09-00 through 10-00-; JP1/Performance Management - Agent Option for JP1/AJS3: from 09-00 through 10-00-; JP1/Performance Management - Agent Option for OpenTP1: from 09-00 through 10-00-; JP1/Performance Management - Agent Option for Oracle WebLogic Server: from 09-00 through 10-00-; JP1/Performance Management - Agent Option for uCosminexus Application Server: from 09-00 through 10-00-; JP1/Performance Management - Agent Option for Virtual Machine: from 09-00 through 09-01-*.

Affected configurations

NVD
Node
microsoftwindowsMatch-
AND
hitachijp1\/performance_managementMatch-

CNA Affected

[
  {
    "defaultStatus": "unaffected",
    "platforms": [
      "Windows"
    ],
    "product": "JP1/Performance Management - Manager",
    "vendor": "Hitachi",
    "versions": [
      {
        "lessThan": "11-50",
        "status": "affected",
        "version": "09-00",
        "versionType": "custom"
      },
      {
        "changes": [
          {
            "at": "11-50-16",
            "status": "unaffected"
          }
        ],
        "lessThan": "11-50-16",
        "status": "affected",
        "version": "11-50",
        "versionType": "custom"
      },
      {
        "changes": [
          {
            "at": "12-00-14",
            "status": "unaffected"
          }
        ],
        "lessThan": "12-00-14",
        "status": "affected",
        "version": "12-00",
        "versionType": "custom"
      },
      {
        "changes": [
          {
            "at": "12-10-08",
            "status": "unaffected"
          }
        ],
        "lessThan": "12-10-08",
        "status": "affected",
        "version": "12-10",
        "versionType": "custom"
      },
      {
        "changes": [
          {
            "at": "12-50-07",
            "status": "unaffected"
          }
        ],
        "lessThan": "12-50-07",
        "status": "affected",
        "version": "12-50",
        "versionType": "custom"
      }
    ]
  },
  {
    "defaultStatus": "unaffected",
    "platforms": [
      "Windows"
    ],
    "product": "JP1/Performance Management - Base",
    "vendor": "Hitachi",
    "versions": [
      {
        "lessThanOrEqual": "10-50-*",
        "status": "affected",
        "version": "09-00",
        "versionType": "custom"
      }
    ]
  },
  {
    "defaultStatus": "unaffected",
    "platforms": [
      "Windows"
    ],
    "product": "JP1/Performance Management - Agent Option for Application Server",
    "vendor": "Hitachi",
    "versions": [
      {
        "changes": [
          {
            "at": "11-50-16",
            "status": "unaffected"
          }
        ],
        "lessThan": "11-50-16",
        "status": "affected",
        "version": "11-00",
        "versionType": "custom"
      }
    ]
  },
  {
    "defaultStatus": "unaffected",
    "platforms": [
      "Windows"
    ],
    "product": "JP1/Performance Management - Agent Option for Enterprise Applications",
    "vendor": "Hitachi",
    "versions": [
      {
        "lessThan": "11-50",
        "status": "affected",
        "version": "09-00",
        "versionType": "custom"
      },
      {
        "changes": [
          {
            "at": "11-50-16",
            "status": "unaffected"
          }
        ],
        "lessThan": "11-50-16",
        "status": "affected",
        "version": "11-50",
        "versionType": "custom"
      },
      {
        "changes": [
          {
            "at": "12-00-14",
            "status": "unaffected"
          }
        ],
        "lessThan": "12-00-14",
        "status": "affected",
        "version": "12-00",
        "versionType": "custom"
      }
    ]
  },
  {
    "defaultStatus": "unaffected",
    "platforms": [
      "Windows"
    ],
    "product": "JP1/Performance Management - Agent Option for HiRDB",
    "vendor": "Hitachi",
    "versions": [
      {
        "lessThan": "11-50",
        "status": "affected",
        "version": "09-00",
        "versionType": "custom"
      },
      {
        "changes": [
          {
            "at": "11-50-16",
            "status": "unaffected"
          }
        ],
        "lessThan": "11-50-16",
        "status": "affected",
        "version": "11-50",
        "versionType": "custom"
      },
      {
        "changes": [
          {
            "at": "12-00-14",
            "status": "unaffected"
          }
        ],
        "lessThan": "12-00-14",
        "status": "affected",
        "version": "12-00",
        "versionType": "custom"
      }
    ]
  },
  {
    "defaultStatus": "unaffected",
    "platforms": [
      "Windows"
    ],
    "product": "JP1/Performance Management - Agent Option for IBM Lotus Domino",
    "vendor": "Hitachi",
    "versions": [
      {
        "changes": [
          {
            "at": "11-50-16",
            "status": "unaffected"
          }
        ],
        "lessThan": "11-50-16",
        "status": "affected",
        "version": "10-00",
        "versionType": "custom"
      }
    ]
  },
  {
    "defaultStatus": "unaffected",
    "platforms": [
      "Windows"
    ],
    "product": "JP1/Performance Management - Agent Option for Microsoft(R) Exchange Server",
    "vendor": "Hitachi",
    "versions": [
      {
        "lessThan": "11-50",
        "status": "affected",
        "version": "09-00",
        "versionType": "custom"
      },
      {
        "changes": [
          {
            "at": "11-50-16",
            "status": "unaffected"
          }
        ],
        "lessThan": "11-50-16",
        "status": "affected",
        "version": "11-50",
        "versionType": "custom"
      },
      {
        "changes": [
          {
            "at": "12-00-14",
            "status": "unaffected"
          }
        ],
        "lessThan": "12-00-14",
        "status": "affected",
        "version": "12-00",
        "versionType": "custom"
      }
    ]
  },
  {
    "defaultStatus": "unaffected",
    "platforms": [
      "Windows"
    ],
    "product": "JP1/Performance Management - Agent Option for Microsoft(R) Internet Information Server",
    "vendor": "Hitachi",
    "versions": [
      {
        "lessThan": "11-50",
        "status": "affected",
        "version": "09-00",
        "versionType": "custom"
      },
      {
        "changes": [
          {
            "at": "11-50-16",
            "status": "unaffected"
          }
        ],
        "lessThan": "11-50-16",
        "status": "affected",
        "version": "11-50",
        "versionType": "custom"
      },
      {
        "changes": [
          {
            "at": "12-00-14",
            "status": "unaffected"
          }
        ],
        "lessThan": "12-00-14",
        "status": "affected",
        "version": "12-00",
        "versionType": "custom"
      }
    ]
  },
  {
    "defaultStatus": "unaffected",
    "platforms": [
      "Windows"
    ],
    "product": "JP1/Performance Management - Agent Option for Microsoft(R) SQL Server",
    "vendor": "Hitachi",
    "versions": [
      {
        "lessThan": "11-50",
        "status": "affected",
        "version": "09-00",
        "versionType": "custom"
      },
      {
        "changes": [
          {
            "at": "11-50-16",
            "status": "unaffected"
          }
        ],
        "lessThan": "11-50-16",
        "status": "affected",
        "version": "11-50",
        "versionType": "custom"
      },
      {
        "changes": [
          {
            "at": "12-00-14",
            "status": "unaffected"
          }
        ],
        "lessThan": "12-00-14",
        "status": "affected",
        "version": "12-00",
        "versionType": "custom"
      },
      {
        "changes": [
          {
            "at": "12-50-07",
            "status": "unaffected"
          }
        ],
        "lessThan": "12-50-07",
        "status": "affected",
        "version": "12-50",
        "versionType": "custom"
      }
    ]
  },
  {
    "defaultStatus": "unaffected",
    "platforms": [
      "Windows"
    ],
    "product": "JP1/Performance Management - Agent Option for Oracle",
    "vendor": "Hitachi",
    "versions": [
      {
        "lessThan": "11-50",
        "status": "affected",
        "version": "09-00",
        "versionType": "custom"
      },
      {
        "changes": [
          {
            "at": "11-50-16",
            "status": "unaffected"
          }
        ],
        "lessThan": "11-50-16",
        "status": "affected",
        "version": "11-50",
        "versionType": "custom"
      },
      {
        "changes": [
          {
            "at": "12-00-14",
            "status": "unaffected"
          }
        ],
        "lessThan": "12-00-14",
        "status": "affected",
        "version": "12-00",
        "versionType": "custom"
      },
      {
        "changes": [
          {
            "at": "12-10-08",
            "status": "unaffected"
          }
        ],
        "lessThan": "12-10-08",
        "status": "affected",
        "version": "12-10",
        "versionType": "custom"
      }
    ]
  },
  {
    "defaultStatus": "unaffected",
    "platforms": [
      "Windows"
    ],
    "product": "JP1/Performance Management - Agent Option for Platform",
    "vendor": "Hitachi",
    "versions": [
      {
        "lessThan": "11-50",
        "status": "affected",
        "version": "09-00",
        "versionType": "custom"
      },
      {
        "changes": [
          {
            "at": "11-50-16",
            "status": "unaffected"
          }
        ],
        "lessThan": "11-50-16",
        "status": "affected",
        "version": "11-50",
        "versionType": "custom"
      },
      {
        "changes": [
          {
            "at": "12-00-14",
            "status": "unaffected"
          }
        ],
        "lessThan": "12-00-14",
        "status": "affected",
        "version": "12-00",
        "versionType": "custom"
      },
      {
        "changes": [
          {
            "at": "12-50-07",
            "status": "unaffected"
          }
        ],
        "lessThan": "12-50-07",
        "status": "affected",
        "version": "12-50",
        "versionType": "custom"
      }
    ]
  },
  {
    "defaultStatus": "unaffected",
    "platforms": [
      "Windows"
    ],
    "product": "JP1/Performance Management - Agent Option for Service Response",
    "vendor": "Hitachi",
    "versions": [
      {
        "changes": [
          {
            "at": "11-50-16",
            "status": "unaffected"
          }
        ],
        "lessThan": "11-50-16",
        "status": "affected",
        "version": "09-00",
        "versionType": "custom"
      }
    ]
  },
  {
    "defaultStatus": "unaffected",
    "platforms": [
      "Windows"
    ],
    "product": "JP1/Performance Management - Agent Option for Transaction System",
    "vendor": "Hitachi",
    "versions": [
      {
        "changes": [
          {
            "at": "11-50-16",
            "status": "unaffected"
          }
        ],
        "lessThan": "11-50-16",
        "status": "affected",
        "version": "11-00",
        "versionType": "custom"
      },
      {
        "changes": [
          {
            "at": "12-00-14",
            "status": "unaffected"
          }
        ],
        "lessThan": "12-00-14",
        "status": "affected",
        "version": "12-00",
        "versionType": "custom"
      }
    ]
  },
  {
    "defaultStatus": "unaffected",
    "platforms": [
      "Windows"
    ],
    "product": "JP1/Performance Management - Remote Monitor for Microsoft(R) SQL Server",
    "vendor": "Hitachi",
    "versions": [
      {
        "lessThan": "11-50",
        "status": "affected",
        "version": "09-00",
        "versionType": "custom"
      },
      {
        "changes": [
          {
            "at": "11-50-16",
            "status": "unaffected"
          }
        ],
        "lessThan": "11-50-16",
        "status": "affected",
        "version": "11-50",
        "versionType": "custom"
      },
      {
        "changes": [
          {
            "at": "12-00-14",
            "status": "unaffected"
          }
        ],
        "lessThan": "12-00-14",
        "status": "affected",
        "version": "12-00",
        "versionType": "custom"
      },
      {
        "changes": [
          {
            "at": "12-50-07",
            "status": "unaffected"
          }
        ],
        "lessThan": "12-50-07",
        "status": "affected",
        "version": "12-50",
        "versionType": "custom"
      }
    ]
  },
  {
    "defaultStatus": "unaffected",
    "platforms": [
      "Windows"
    ],
    "product": "JP1/Performance Management - Remote Monitor for Oracle",
    "vendor": "Hitachi",
    "versions": [
      {
        "lessThan": "11-50",
        "status": "affected",
        "version": "09-00",
        "versionType": "custom"
      },
      {
        "changes": [
          {
            "at": "11-50-16",
            "status": "unaffected"
          }
        ],
        "lessThan": "11-50-16",
        "status": "affected",
        "version": "11-50",
        "versionType": "custom"
      },
      {
        "changes": [
          {
            "at": "12-00-14",
            "status": "unaffected"
          }
        ],
        "lessThan": "12-00-14",
        "status": "affected",
        "version": "12-00",
        "versionType": "custom"
      },
      {
        "changes": [
          {
            "at": "12-10-08",
            "status": "unaffected"
          }
        ],
        "lessThan": "12-10-08",
        "status": "affected",
        "version": "12-10",
        "versionType": "custom"
      }
    ]
  },
  {
    "defaultStatus": "unaffected",
    "platforms": [
      "Windows"
    ],
    "product": "JP1/Performance Management - Remote Monitor for Platform",
    "vendor": "Hitachi",
    "versions": [
      {
        "lessThan": "11-50",
        "status": "affected",
        "version": "09-00",
        "versionType": "custom"
      },
      {
        "changes": [
          {
            "at": "11-50-16",
            "status": "unaffected"
          }
        ],
        "lessThan": "11-50-16",
        "status": "affected",
        "version": "11-50",
        "versionType": "custom"
      },
      {
        "changes": [
          {
            "at": "12-00-14",
            "status": "unaffected"
          }
        ],
        "lessThan": "12-00-14",
        "status": "affected",
        "version": "12-00",
        "versionType": "custom"
      },
      {
        "changes": [
          {
            "at": "12-10-08",
            "status": "unaffected"
          }
        ],
        "lessThan": "12-10-08",
        "status": "affected",
        "version": "12-10",
        "versionType": "custom"
      }
    ]
  },
  {
    "defaultStatus": "unaffected",
    "platforms": [
      "Windows"
    ],
    "product": "JP1/Performance Management - Remote Monitor for Virtual Machine",
    "vendor": "Hitachi",
    "versions": [
      {
        "lessThan": "11-50",
        "status": "affected",
        "version": "10-00",
        "versionType": "custom"
      },
      {
        "changes": [
          {
            "at": "11-50-16",
            "status": "unaffected"
          }
        ],
        "lessThan": "11-50-16",
        "status": "affected",
        "version": "11-50",
        "versionType": "custom"
      },
      {
        "changes": [
          {
            "at": "12-00-14",
            "status": "unaffected"
          }
        ],
        "lessThan": "12-00-14",
        "status": "affected",
        "version": "12-00",
        "versionType": "custom"
      },
      {
        "changes": [
          {
            "at": "12-10-08",
            "status": "unaffected"
          }
        ],
        "lessThan": "12-10-08",
        "status": "affected",
        "version": "12-10",
        "versionType": "custom"
      },
      {
        "changes": [
          {
            "at": "12-50-07",
            "status": "unaffected"
          }
        ],
        "lessThan": "12-50-07",
        "status": "affected",
        "version": "12-50",
        "versionType": "custom"
      }
    ]
  },
  {
    "defaultStatus": "unaffected",
    "platforms": [
      "Windows"
    ],
    "product": "JP1/Performance Management - Agent Option for Domino",
    "vendor": "Hitachi",
    "versions": [
      {
        "lessThanOrEqual": "09-00-*",
        "status": "affected",
        "version": "09-00",
        "versionType": "custom"
      }
    ]
  },
  {
    "defaultStatus": "unaffected",
    "platforms": [
      "Windows"
    ],
    "product": "JP1/Performance Management - Agent Option for IBM WebSphere Application Server",
    "vendor": "Hitachi",
    "versions": [
      {
        "lessThanOrEqual": "10-00-*",
        "status": "affected",
        "version": "09-00",
        "versionType": "custom"
      }
    ]
  },
  {
    "defaultStatus": "unaffected",
    "platforms": [
      "Windows"
    ],
    "product": "JP1/Performance Management - Agent Option for IBM WebSphere MQ",
    "vendor": "Hitachi",
    "versions": [
      {
        "lessThanOrEqual": "10-00-*",
        "status": "affected",
        "version": "09-00",
        "versionType": "custom"
      }
    ]
  },
  {
    "defaultStatus": "unaffected",
    "platforms": [
      "Windows"
    ],
    "product": "JP1/Performance Management - Agent Option for JP1/AJS3",
    "vendor": "Hitachi",
    "versions": [
      {
        "lessThanOrEqual": "10-00-*",
        "status": "affected",
        "version": "09-00",
        "versionType": "custom"
      }
    ]
  },
  {
    "defaultStatus": "unaffected",
    "platforms": [
      "Windows"
    ],
    "product": "JP1/Performance Management - Agent Option for OpenTP1",
    "vendor": "Hitachi",
    "versions": [
      {
        "lessThanOrEqual": "10-00-*",
        "status": "affected",
        "version": "09-00",
        "versionType": "custom"
      }
    ]
  },
  {
    "defaultStatus": "unaffected",
    "platforms": [
      "Windows"
    ],
    "product": "JP1/Performance Management - Agent Option for Oracle WebLogic Server",
    "vendor": "Hitachi",
    "versions": [
      {
        "lessThanOrEqual": "10-00-*",
        "status": "affected",
        "version": "09-00",
        "versionType": "custom"
      }
    ]
  },
  {
    "defaultStatus": "unaffected",
    "platforms": [
      "Windows"
    ],
    "product": "JP1/Performance Management - Agent Option for uCosminexus Application Server",
    "vendor": "Hitachi",
    "versions": [
      {
        "lessThanOrEqual": "10-00-*",
        "status": "affected",
        "version": "09-00",
        "versionType": "custom"
      }
    ]
  },
  {
    "defaultStatus": "unaffected",
    "platforms": [
      "Windows"
    ],
    "product": "JP1/Performance Management - Agent Option for Virtual Machine",
    "vendor": "Hitachi",
    "versions": [
      {
        "lessThanOrEqual": "09-01-*",
        "status": "affected",
        "version": "09-00",
        "versionType": "custom"
      }
    ]
  }
]

8.4 High

CVSS3

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

7.6 High

AI Score

Confidence

High

0.0004 Low

EPSS

Percentile

9.1%

Related for CVE-2023-3440