cbcvebase.
CVE-2023-37536
published 2023-10-11

CVE-2023-37536: An integer overflow in xerces-c++ 3.2.3 in BigFix Platform allows remote attackers to cause out-of-bound access via HTTP request.

high8.8CVSS 3.1
AVNACLPRLUINSUCHIHAH
An integer overflow in xerces-c++ 3.2.3 in BigFix Platform allows remote attackers to cause out-of-bound access via HTTP request.

Affected

15 ranges
VendorProductVersion rangeFixed in
apachexerces-c
apachexerces-c>= 0 < 3.2.3+debian-3+deb11u13.2.3+debian-3+deb11u1
apachexerces-c>= 0 < 3.2.4+debian-13.2.4+debian-1
apachexerces-c>= 0 < 3.2.4+debian-13.2.4+debian-1
apachexerces-c>= 0 < 3.2.4+debian-13.2.4+debian-1
apachexerces-c>= 0 < 3.2.2+debian-1ubuntu0.23.2.2+debian-1ubuntu0.2
apachexerces-c>= 0 < 3.2.3+debian-3ubuntu0.13.2.3+debian-3ubuntu0.1
apachexerces-c>= 0 < 3.1.1-5.1+deb8u4ubuntu0.1~esm23.1.1-5.1+deb8u4ubuntu0.1~esm2
apachexerces-c>= 0 < 3.1.3+debian-1ubuntu0.1~esm33.1.3+debian-1ubuntu0.1~esm3
apachexerces-c>= 0 < 3.2.0+debian-2ubuntu0.1~esm33.2.0+debian-2ubuntu0.1~esm3
debianxerces-c< xerces-c 3.2.4+debian-1 (bookworm)xerces-c 3.2.4+debian-1 (bookworm)
fedoraprojectfedora
hcl_softwarebigfix_platform
hcltechbigfix_platform>= 10.0.0 < 10.0.1010.0.10
hcltechbigfix_platform>= 9.0.0 < 9.5.239.5.23

CVSS provenance

nvdv3.18.8HIGHCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
osv8.8HIGH