PT-2023-5924 · Hitachi+3 · Hitachi Jp1/Performance Management - Remote Monitor For Oracle+29
Masaya Suzuki
+1
·
Published
2023-07-21
·
Updated
2023-10-16
·
CVE-2023-3440
CVSS v3.1
8.4
High
| Vector | AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Hitachi JP1/Performance Management - Manager versions 09-00 through 12-50-06
Hitachi JP1/Performance Management - Base versions 09-00 through 10-50-*
Hitachi JP1/Performance Management - Agent Option for Application Server versions 11-00 through 11-50-15
Hitachi JP1/Performance Management - Agent Option for Enterprise Applications versions 09-00 through 12-00-13
Hitachi JP1/Performance Management - Agent Option for HiRDB versions 09-00 through 12-00-13
Hitachi JP1/Performance Management - Agent Option for IBM Lotus Domino versions 10-00 through 11-50-15
Hitachi JP1/Performance Management - Agent Option for Microsoft(R) Exchange Server versions 09-00 through 12-00-13
Hitachi JP1/Performance Management - Agent Option for Microsoft(R) Internet Information Server versions 09-00 through 12-00-13
Hitachi JP1/Performance Management - Agent Option for Microsoft(R) SQL Server versions 09-00 through 12-50-06
Hitachi JP1/Performance Management - Agent Option for Oracle versions 09-00 through 12-10-07
Hitachi JP1/Performance Management - Agent Option for Platform versions 09-00 through 12-50-06
Hitachi JP1/Performance Management - Agent Option for Service Response versions 09-00 through 11-50-15
Hitachi JP1/Performance Management - Agent Option for Transaction System versions 11-00 through 12-00-13
Hitachi JP1/Performance Management - Remote Monitor for Microsoft(R) SQL Server versions 09-00 through 12-50-06
Hitachi JP1/Performance Management - Remote Monitor for Oracle versions 09-00 through 12-10-07
Hitachi JP1/Performance Management - Remote Monitor for Platform versions 09-00 through 12-10-07
Hitachi JP1/Performance Management - Remote Monitor for Virtual Machine versions 10-00 through 12-50-06
Hitachi JP1/Performance Management - Agent Option for Domino version 09-00
Hitachi JP1/Performance Management - Agent Option for IBM WebSphere Application Server versions 09-00 through 10-00-*
Hitachi JP1/Performance Management - Agent Option for IBM WebSphere MQ versions 09-00 through 10-00-*
Hitachi JP1/Performance Management - Agent Option for JP1/AJS3 versions 09-00 through 10-00-*
Hitachi JP1/Performance Management - Agent Option for OpenTP1 versions 09-00 through 10-00-*
Hitachi JP1/Performance Management - Agent Option for Oracle WebLogic Server versions 09-00 through 10-00-*
Hitachi JP1/Performance Management - Agent Option for uCosminexus Application Server versions 09-00 through 10-00-*
Hitachi JP1/Performance Management - Agent Option for Virtual Machine versions 09-00 through 09-01-*
Description
The issue is related to incorrect default permissions in Hitachi JP1/Performance Management on Windows, allowing file manipulation. This can enable an attacker to access files and directories.
Recommendations
For Hitachi JP1/Performance Management - Manager versions 09-00 through 12-50-06, update to a version after 12-50-06.
For Hitachi JP1/Performance Management - Base versions 09-00 through 10-50-, update to a version after 10-50-.
For Hitachi JP1/Performance Management - Agent Option for Application Server versions 11-00 through 11-50-15, update to a version after 11-50-15.
For Hitachi JP1/Performance Management - Agent Option for Enterprise Applications versions 09-00 through 12-00-13, update to a version after 12-00-13.
For Hitachi JP1/Performance Management - Agent Option for HiRDB versions 09-00 through 12-00-13, update to a version after 12-00-13.
For Hitachi JP1/Performance Management - Agent Option for IBM Lotus Domino versions 10-00 through 11-50-15, update to a version after 11-50-15.
For Hitachi JP1/Performance Management - Agent Option for Microsoft(R) Exchange Server versions 09-00 through 12-00-13, update to a version after 12-00-13.
For Hitachi JP1/Performance Management - Agent Option for Microsoft(R) Internet Information Server versions 09-00 through 12-00-13, update to a version after 12-00-13.
For Hitachi JP1/Performance Management - Agent Option for Microsoft(R) SQL Server versions 09-00 through 12-50-06, update to a version after 12-50-06.
For Hitachi JP1/Performance Management - Agent Option for Oracle versions 09-00 through 12-10-07, update to a version after 12-10-07.
For Hitachi JP1/Performance Management - Agent Option for Platform versions 09-00 through 12-50-06, update to a version after 12-50-06.
For Hitachi JP1/Performance Management - Agent Option for Service Response versions 09-00 through 11-50-15, update to a version after 11-50-15.
For Hitachi JP1/Performance Management - Agent Option for Transaction System versions 11-00 through 12-00-13, update to a version after 12-00-13.
For Hitachi JP1/Performance Management - Remote Monitor for Microsoft(R) SQL Server versions 09-00 through 12-50-06, update to a version after 12-50-06.
For Hitachi JP1/Performance Management - Remote Monitor for Oracle versions 09-00 through 12-10-07, update to a version after 12-10-07.
For Hitachi JP1/Performance Management - Remote Monitor for Platform versions 09-00 through 12-10-07, update to a version after 12-10-07.
For Hitachi JP1/Performance Management - Remote Monitor for Virtual Machine versions 10-00 through 12-50-06, update to a version after 12-50-06.
For Hitachi JP1/Performance Management - Agent Option for Domino version 09-00, update to a version after 09-00.
For Hitachi JP1/Performance Management - Agent Option for IBM WebSphere Application Server versions 09-00 through 10-00-, update to a version after 10-00-.
For Hitachi JP1/Performance Management - Agent Option for IBM WebSphere MQ versions 09-00 through 10-00-, update to a version after 10-00-.
For Hitachi JP1/Performance Management - Agent Option for JP1/AJS3 versions 09-00 through 10-00-, update to a version after 10-00-.
For Hitachi JP1/Performance Management - Agent Option for OpenTP1 versions 09-00 through 10-00-, update to a version after 10-00-.
For Hitachi JP1/Performance Management - Agent Option for Oracle WebLogic Server versions 09-00 through 10-00-, update to a version after 10-00-.
For Hitachi JP1/Performance Management - Agent Option for uCosminexus Application Server versions 09-00 through 10-00-, update to a version after 10-00-.
For Hitachi JP1/Performance Management - Agent Option for Virtual Machine versions 09-00 through 09-01-, update to a version after 09-01-.
Fix
Incorrect Default Permissions
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Hitachi Jp1/Performance Management - Agent Option For Application Server
Hitachi Jp1/Performance Management - Agent Option For Domino
Hitachi Jp1/Performance Management - Agent Option For Enterprise Applications
Hitachi Jp1/Performance Management - Agent Option For Hirdb
Hitachi Jp1/Performance Management - Agent Option For Ibm Websphere Application Server
Hitachi Jp1/Performance Management - Agent Option For Ibm Websphere Mq
Hitachi Jp1/Performance Management - Agent Option For Jp1/Ajs3
Hitachi Jp1/Performance Management - Agent Option For Microsoft Exchange Server
Hitachi Jp1/Performance Management - Agent Option For Microsoft Internet Information Server
Hitachi Jp1/Performance Management - Agent Option For Opentp1
Hitachi Jp1/Performance Management - Agent Option For Oracle
Hitachi Jp1/Performance Management - Agent Option For Oracle Weblogic Server
Hitachi Jp1/Performance Management - Agent Option For Platform
Hitachi Jp1/Performance Management - Agent Option For Service Response
Hitachi Jp1/Performance Management - Agent Option For Transaction System
Hitachi Jp1/Performance Management - Agent Option For Virtual Machine
Hitachi Jp1/Performance Management - Base
Hitachi Jp1/Performance Management - Manager
Hitachi Jp1/Performance Management - Remote Monitor For Microsoft Sql Server
Hitachi Jp1/Performance Management - Remote Monitor For Oracle
Hitachi Jp1/Performance Management - Remote Monitor For Platform
Hitachi Jp1/Performance Management - Remote Monitor For Virtual Machine
Ibm Lotus Domino
Ibm Websphere Application Server
Ibm Websphere Mq
Exchange Server
Internet Information Server
Sql Server
Oracle
Oracle Weblogic Server