CVE-2023-37536 — Integer Overflow or Wraparound in Bigfix Platform
Severity
8.8HIGHNVD
CNA8.2
EPSS
1.1%
top 22.09%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedOct 11
Latest updateApr 15
Description
An integer overflow in xerces-c++ 3.2.3 in BigFix Platform allows remote attackers to cause out-of-bound access via HTTP request.
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:HExploitability: 2.8 | Impact: 5.9
Affected Packages4 packages
Also affects: Fedora 37
🔴Vulnerability Details
3📋Vendor Advisories
7Oracle▶
Oracle Oracle Supply Chain Risk Matrix: Forecast Engine (Apache Xerces-C++) — CVE-2023-37536↗2025-04-15
Oracle▶
Oracle Oracle Essbase Risk Matrix: Essbase Web Platform (Apache Xerces-C++) — CVE-2023-37536↗2024-07-15
Oracle▶
Oracle Oracle Fusion Middleware Risk Matrix: Webserver Plugin (Apache Xerces-C++) — CVE-2023-37536↗2024-04-15
Oracle▶
Oracle Oracle Communications Applications Risk Matrix: Security (Apache Xerces-C++) — CVE-2023-37536↗2024-01-15