CVE-2023-1995

HIGHCVSS 7.5/10EPSS 0.38%

Last modified

CVE-2023-1995 is a high-severity vulnerability rated 7.5/10 on the CVSS scale. Insufficient Logging vulnerability in Hitachi HiRDB Server, HiRDB Server With Addtional Function, HiRDB Structured Data Access Facility.This issue affects HiRDB Server: before 09-60-39, before 09-65-23, before 09-66-17, before 10-01-10, before 10-03-12, before 10-04-06, before 10-05-06, before 10-06-02; HiRDB Server With Addtional Function: before 09-60-2M, before 09-65-/W , before 09-66-/Q ; HiRDB Structured Data Access Facility: before 09-60-39, before 10-03-12, before 10-04-06, before 10-06-02. . EPSS estimates a 0.38% chance of exploitation in the next 30 days.

Description

Insufficient Logging vulnerability in Hitachi HiRDB Server, HiRDB Server With Addtional Function, HiRDB Structured Data Access Facility.This issue affects HiRDB Server: before 09-60-39, before 09-65-23, before 09-66-17, before 10-01-10, before 10-03-12, before 10-04-06, before 10-05-06, before 10-06-02; HiRDB Server With Addtional Function: before 09-60-2M, before 09-65-/W , before 09-66-/Q ; HiRDB Structured Data Access Facility: before 09-60-39, before 10-03-12, before 10-04-06, before 10-06-02.

Metrics

CVSS 3.1
7.5/10

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N

EPSS Probability
0.38%

29.5th percentile

Probability of exploitation in the next 30 days. Learn more

Weakness Enumeration

Affected Software

VendorProductVersions
HitachiHirdb Server With Additional Function>= 09-00, <= 09-00-2d
HitachiHirdb Server With Additional Function>= 09-01, <= 09-01-\/x
HitachiHirdb Server With Additional Function>= 09-02, <= 09-02-2f
HitachiHirdb Server With Additional Function>= 09-03, <= 09-03-2a
HitachiHirdb Server With Additional Function>= 09-04, <= 09-04-2s
HitachiHirdb Server With Additional Function>= 09-50, <= 09-50-2k
HitachiHirdb Server With Additional Function>= 09-60, <= 09-60-2k
HitachiHirdb Server With Additional Function>= 09-65, <= 09-65-\/v
HitachiHirdb Server With Additional Function>= 09-66, <= 09-66-\/p
HitachiHirdb Server With Additional Function>= 09-00, <= 09-00-2f
HitachiHirdb Server With Additional Function>= 09-03, <= 09-03-2e
HitachiHirdb Server With Additional Function>= 09-60, <= 09-60-2l
HitachiHirdb Structured Data Access Facility>= 09-60, <= 09-60-37
HitachiHirdb Structured Data Access Facility>= 09-66, <= 09-66-06
HitachiHirdb Structured Data Access Facility>= 10-01, <= 10-01-03
HitachiHirdb Structured Data Access Facility>= 10-02, <= 10-02-12
HitachiHirdb Structured Data Access Facility>= 10-03, <= 10-03-10
HitachiHirdb Structured Data Access Facility>= 10-04, <= 10-04-05
HitachiHirdb Structured Data Access Facility>= 10-06, <= 10-06-01
HitachiHirdb Server>= 09-00, <= 09-00-30
HitachiHirdb Server>= 09-01, <= 09-01-24
HitachiHirdb Server>= 09-02, <= 09-02-32
HitachiHirdb Server>= 09-03, <= 09-03-27
HitachiHirdb Server>= 09-04, <= 09-04-31
HitachiHirdb Server>= 09-00, <= 09-00-32
HitachiHirdb Server>= 09-03, <= 09-03-31
HitachiHirdb Server>= 09-04, <= 09-04-45
HitachiHirdb Server>= 09-50, <= 09-50-37
HitachiHirdb Server>= 09-60, <= 09-60-38
HitachiHirdb Server>= 09-65, <= 09-65-22
HitachiHirdb Server>= 09-66, <= 09-66-16
HitachiHirdb Server>= 10-00, <= 10-00-09
HitachiHirdb Server>= 10-01, <= 10-01-09
HitachiHirdb Server>= 10-02, <= 10-02-12
HitachiHirdb Server>= 10-03, <= 10-03-11
HitachiHirdb Server>= 10-04, <= 10-04-04
HitachiHirdb Server>= 10-05, <= 10-05-05
HitachiHirdb Server>= 10-06, <= 10-06-01
HitachiHirdb Server>= 10-03, <= 10-03-10
HitachiHirdb Server>= 10-04, <= 10-04-05
HitachiHirdb Server>= 09-60, <= 09-60-37

References

Timeline

Published
Last Modified
Status
Modified

Frequently Asked Questions

What is CVE-2023-1995?
Insufficient Logging vulnerability in Hitachi HiRDB Server, HiRDB Server With Addtional Function, HiRDB Structured Data Access Facility.This issue affects HiRDB Server: before 09-60-39, before 09-65-23, before 09-66-17, before 10-01-10, before 10-03-12, before 10-04-06, before 10-05-06, before 10-06-02; HiRDB Server With Addtional Function: before 09-60-2M, before 09-65-/W , before 09-66-/Q ; HiRDB Structured Data Access Facility: before 09-60-39, before 10-03-12, before 10-04-06, before 10-06-02.
How severe is CVE-2023-1995?
CVE-2023-1995 has a CVSS score of 7.5/10 (HIGH severity). The EPSS model estimates a 0.38% probability of exploitation in the next 30 days.
How do I fix CVE-2023-1995?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.

Are you affected by CVE-2023-1995?

Run a free Strix scan to check your systems for this vulnerability.

Scan your code now

Source: NVD / NIST