CVE-2023-37519Cross-site Scripting in Bigfix Platform

Severity
6.1MEDIUMNVD
CNA7.7
EPSS
0.2%
top 63.03%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedDec 21
Latest updateDec 22

Description

Unauthenticated Stored Cross-Site Scripting (XSS) vulnerability. This XSS vulnerability is in the Download Status Report, which is served by the BigFix Server.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:NExploitability: 2.8 | Impact: 2.7

Affected Packages2 packages

NVDhcltech/bigfix_platform9.59.5.23+2
CVEListV5hcl_software/hcl_bigfix_platform9.5.x, 10.0.x

🔴Vulnerability Details

2
GHSA
GHSA-xhgw-9c9f-wj5v: Unauthenticated Stored Cross-Site Scripting (XSS) vulnerability2023-12-22
CVEList
HCL BigFix Platform is affected by Unathenticated Stored Cross-Site Scripting (XSS)2023-12-21

📋Vendor Advisories

1
Oracle
Oracle Oracle Communications Risk Matrix: Patches (memcached) — CVE-2021-375192023-04-15
CVE-2023-37519 — Cross-site Scripting | cvebase