CVE-2023-37536Integer Overflow or Wraparound in Bigfix Platform

Severity
8.8HIGHNVD
CNA8.2
EPSS
1.1%
top 22.09%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedOct 11
Latest updateApr 15

Description

An integer overflow in xerces-c++ 3.2.3 in BigFix Platform allows remote attackers to cause out-of-bound access via HTTP request.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:HExploitability: 2.8 | Impact: 5.9

Affected Packages4 packages

NVDhcltech/bigfix_platform9.0.09.5.23+1
CVEListV5hcl_software/bigfix_platform9.5 - 9.5.22, 10 - 10.0.9
Debianapache/xerces-c< 3.2.3+debian-3+deb11u1+3
NVDapache/xerces-c3.2.3

Also affects: Fedora 37

🔴Vulnerability Details

3
CVEList
HCL BigFix Platform is vulnerable to an integer overflow in xerces-c++ 3.2.32023-10-11
GHSA
GHSA-62mq-p983-gjvx: An integer overflow in xerces-c++ 32023-10-11
OSV
CVE-2023-37536: An integer overflow in xerces-c++ 32023-10-11

📋Vendor Advisories

7
Oracle
Oracle Oracle Supply Chain Risk Matrix: Forecast Engine (Apache Xerces-C++) — CVE-2023-375362025-04-15
Oracle
Oracle Oracle Essbase Risk Matrix: Essbase Web Platform (Apache Xerces-C++) — CVE-2023-375362024-07-15
Oracle
Oracle Oracle Fusion Middleware Risk Matrix: Webserver Plugin (Apache Xerces-C++) — CVE-2023-375362024-04-15
Ubuntu
Xerces-C++ vulnerabilities2024-01-18
Oracle
Oracle Oracle Communications Applications Risk Matrix: Security (Apache Xerces-C++) — CVE-2023-375362024-01-15
CVE-2023-37536 — Integer Overflow or Wraparound | cvebase