PT-2023-5924 · Hitachi+3 · Hitachi Jp1/Performance Management - Remote Monitor For Oracle+29

Masaya Suzuki

+1

·

Published

2023-07-21

·

Updated

2023-10-16

·

CVE-2023-3440

CVSS v3.1

8.4

High

VectorAV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Hitachi JP1/Performance Management - Manager versions 09-00 through 12-50-06 Hitachi JP1/Performance Management - Base versions 09-00 through 10-50-* Hitachi JP1/Performance Management - Agent Option for Application Server versions 11-00 through 11-50-15 Hitachi JP1/Performance Management - Agent Option for Enterprise Applications versions 09-00 through 12-00-13 Hitachi JP1/Performance Management - Agent Option for HiRDB versions 09-00 through 12-00-13 Hitachi JP1/Performance Management - Agent Option for IBM Lotus Domino versions 10-00 through 11-50-15 Hitachi JP1/Performance Management - Agent Option for Microsoft(R) Exchange Server versions 09-00 through 12-00-13 Hitachi JP1/Performance Management - Agent Option for Microsoft(R) Internet Information Server versions 09-00 through 12-00-13 Hitachi JP1/Performance Management - Agent Option for Microsoft(R) SQL Server versions 09-00 through 12-50-06 Hitachi JP1/Performance Management - Agent Option for Oracle versions 09-00 through 12-10-07 Hitachi JP1/Performance Management - Agent Option for Platform versions 09-00 through 12-50-06 Hitachi JP1/Performance Management - Agent Option for Service Response versions 09-00 through 11-50-15 Hitachi JP1/Performance Management - Agent Option for Transaction System versions 11-00 through 12-00-13 Hitachi JP1/Performance Management - Remote Monitor for Microsoft(R) SQL Server versions 09-00 through 12-50-06 Hitachi JP1/Performance Management - Remote Monitor for Oracle versions 09-00 through 12-10-07 Hitachi JP1/Performance Management - Remote Monitor for Platform versions 09-00 through 12-10-07 Hitachi JP1/Performance Management - Remote Monitor for Virtual Machine versions 10-00 through 12-50-06 Hitachi JP1/Performance Management - Agent Option for Domino version 09-00 Hitachi JP1/Performance Management - Agent Option for IBM WebSphere Application Server versions 09-00 through 10-00-* Hitachi JP1/Performance Management - Agent Option for IBM WebSphere MQ versions 09-00 through 10-00-* Hitachi JP1/Performance Management - Agent Option for JP1/AJS3 versions 09-00 through 10-00-* Hitachi JP1/Performance Management - Agent Option for OpenTP1 versions 09-00 through 10-00-* Hitachi JP1/Performance Management - Agent Option for Oracle WebLogic Server versions 09-00 through 10-00-* Hitachi JP1/Performance Management - Agent Option for uCosminexus Application Server versions 09-00 through 10-00-* Hitachi JP1/Performance Management - Agent Option for Virtual Machine versions 09-00 through 09-01-*
Description The issue is related to incorrect default permissions in Hitachi JP1/Performance Management on Windows, allowing file manipulation. This can enable an attacker to access files and directories.
Recommendations For Hitachi JP1/Performance Management - Manager versions 09-00 through 12-50-06, update to a version after 12-50-06. For Hitachi JP1/Performance Management - Base versions 09-00 through 10-50-, update to a version after 10-50-. For Hitachi JP1/Performance Management - Agent Option for Application Server versions 11-00 through 11-50-15, update to a version after 11-50-15. For Hitachi JP1/Performance Management - Agent Option for Enterprise Applications versions 09-00 through 12-00-13, update to a version after 12-00-13. For Hitachi JP1/Performance Management - Agent Option for HiRDB versions 09-00 through 12-00-13, update to a version after 12-00-13. For Hitachi JP1/Performance Management - Agent Option for IBM Lotus Domino versions 10-00 through 11-50-15, update to a version after 11-50-15. For Hitachi JP1/Performance Management - Agent Option for Microsoft(R) Exchange Server versions 09-00 through 12-00-13, update to a version after 12-00-13. For Hitachi JP1/Performance Management - Agent Option for Microsoft(R) Internet Information Server versions 09-00 through 12-00-13, update to a version after 12-00-13. For Hitachi JP1/Performance Management - Agent Option for Microsoft(R) SQL Server versions 09-00 through 12-50-06, update to a version after 12-50-06. For Hitachi JP1/Performance Management - Agent Option for Oracle versions 09-00 through 12-10-07, update to a version after 12-10-07. For Hitachi JP1/Performance Management - Agent Option for Platform versions 09-00 through 12-50-06, update to a version after 12-50-06. For Hitachi JP1/Performance Management - Agent Option for Service Response versions 09-00 through 11-50-15, update to a version after 11-50-15. For Hitachi JP1/Performance Management - Agent Option for Transaction System versions 11-00 through 12-00-13, update to a version after 12-00-13. For Hitachi JP1/Performance Management - Remote Monitor for Microsoft(R) SQL Server versions 09-00 through 12-50-06, update to a version after 12-50-06. For Hitachi JP1/Performance Management - Remote Monitor for Oracle versions 09-00 through 12-10-07, update to a version after 12-10-07. For Hitachi JP1/Performance Management - Remote Monitor for Platform versions 09-00 through 12-10-07, update to a version after 12-10-07. For Hitachi JP1/Performance Management - Remote Monitor for Virtual Machine versions 10-00 through 12-50-06, update to a version after 12-50-06. For Hitachi JP1/Performance Management - Agent Option for Domino version 09-00, update to a version after 09-00. For Hitachi JP1/Performance Management - Agent Option for IBM WebSphere Application Server versions 09-00 through 10-00-, update to a version after 10-00-. For Hitachi JP1/Performance Management - Agent Option for IBM WebSphere MQ versions 09-00 through 10-00-, update to a version after 10-00-. For Hitachi JP1/Performance Management - Agent Option for JP1/AJS3 versions 09-00 through 10-00-, update to a version after 10-00-. For Hitachi JP1/Performance Management - Agent Option for OpenTP1 versions 09-00 through 10-00-, update to a version after 10-00-. For Hitachi JP1/Performance Management - Agent Option for Oracle WebLogic Server versions 09-00 through 10-00-, update to a version after 10-00-. For Hitachi JP1/Performance Management - Agent Option for uCosminexus Application Server versions 09-00 through 10-00-, update to a version after 10-00-. For Hitachi JP1/Performance Management - Agent Option for Virtual Machine versions 09-00 through 09-01-, update to a version after 09-01-.

Fix

Incorrect Default Permissions

Weakness Enumeration

Related Identifiers

BDU:2023-06620
CVE-2023-3440

Affected Products

Hitachi Jp1/Performance Management - Agent Option For Application Server
Hitachi Jp1/Performance Management - Agent Option For Domino
Hitachi Jp1/Performance Management - Agent Option For Enterprise Applications
Hitachi Jp1/Performance Management - Agent Option For Hirdb
Hitachi Jp1/Performance Management - Agent Option For Ibm Websphere Application Server
Hitachi Jp1/Performance Management - Agent Option For Ibm Websphere Mq
Hitachi Jp1/Performance Management - Agent Option For Jp1/Ajs3
Hitachi Jp1/Performance Management - Agent Option For Microsoft Exchange Server
Hitachi Jp1/Performance Management - Agent Option For Microsoft Internet Information Server
Hitachi Jp1/Performance Management - Agent Option For Opentp1
Hitachi Jp1/Performance Management - Agent Option For Oracle
Hitachi Jp1/Performance Management - Agent Option For Oracle Weblogic Server
Hitachi Jp1/Performance Management - Agent Option For Platform
Hitachi Jp1/Performance Management - Agent Option For Service Response
Hitachi Jp1/Performance Management - Agent Option For Transaction System
Hitachi Jp1/Performance Management - Agent Option For Virtual Machine
Hitachi Jp1/Performance Management - Base
Hitachi Jp1/Performance Management - Manager
Hitachi Jp1/Performance Management - Remote Monitor For Microsoft Sql Server
Hitachi Jp1/Performance Management - Remote Monitor For Oracle
Hitachi Jp1/Performance Management - Remote Monitor For Platform
Hitachi Jp1/Performance Management - Remote Monitor For Virtual Machine
Ibm Lotus Domino
Ibm Websphere Application Server
Ibm Websphere Mq
Exchange Server
Internet Information Server
Sql Server
Oracle
Oracle Weblogic Server