CVE-2023-37536
published 2023-10-11CVE-2023-37536: An integer overflow in xerces-c++ 3.2.3 in BigFix Platform allows remote attackers to cause out-of-bound access via HTTP request.
PriorityP350high8.8CVSS 3.1
AVNACLPRLUINSUCHIHAH
EPSS
1.38%
69.1th percentile
An integer overflow in xerces-c++ 3.2.3 in BigFix Platform allows remote attackers to cause out-of-bound access via HTTP request.
Affected
15 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apache | xerces-c | — | — |
| apache | xerces-c | >= 0 < 3.2.3+debian-3+deb11u1 | 3.2.3+debian-3+deb11u1 |
| apache | xerces-c | >= 0 < 3.2.4+debian-1 | 3.2.4+debian-1 |
| apache | xerces-c | >= 0 < 3.2.4+debian-1 | 3.2.4+debian-1 |
| apache | xerces-c | >= 0 < 3.2.4+debian-1 | 3.2.4+debian-1 |
| apache | xerces-c | >= 0 < 3.2.2+debian-1ubuntu0.2 | 3.2.2+debian-1ubuntu0.2 |
| apache | xerces-c | >= 0 < 3.2.3+debian-3ubuntu0.1 | 3.2.3+debian-3ubuntu0.1 |
| apache | xerces-c | >= 0 < 3.1.1-5.1+deb8u4ubuntu0.1~esm2 | 3.1.1-5.1+deb8u4ubuntu0.1~esm2 |
| apache | xerces-c | >= 0 < 3.1.3+debian-1ubuntu0.1~esm3 | 3.1.3+debian-1ubuntu0.1~esm3 |
| apache | xerces-c | >= 0 < 3.2.0+debian-2ubuntu0.1~esm3 | 3.2.0+debian-2ubuntu0.1~esm3 |
| debian | xerces-c | < xerces-c 3.2.4+debian-1 (bookworm) | xerces-c 3.2.4+debian-1 (bookworm) |
| fedoraproject | fedora | — | — |
| hcl_software | bigfix_platform | — | — |
| hcltech | bigfix_platform | >= 10.0.0 < 10.0.10 | 10.0.10 |
| hcltech | bigfix_platform | >= 9.0.0 < 9.5.23 | 9.5.23 |
CVSS provenance
nvdv3.18.8HIGHCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
osv8.8HIGH
vendor_oracle8.8HIGH
vendor_debian8.2HIGH
vendor_redhat8.2HIGH
vendor_ubuntu8.1HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Oracle
Oracle Oracle Supply Chain Risk Matrix: Forecast Engine (Apache Xerces-C++) — CVE-2023-37536
vendor_oracle·2025-04-15·CVSS 8.8
CVE-2023-37536 [HIGH] Oracle Oracle Supply Chain Risk Matrix: Forecast Engine (Apache Xerces-C++) — CVE-2023-37536
Oracle Oracle Supply Chain Risk Matrix: Forecast Engine (Apache Xerces-C++) vulnerability
CVE: CVE-2023-37536
CVSS: 8.8
Protocol: HTTP
Remote exploit: No
Affected versions: Network
Advisory: cpuapr2025 (APR 2025)
Oracle
Oracle Oracle Essbase Risk Matrix: Essbase Web Platform (Apache Xerces-C++) — CVE-2023-37536
vendor_oracle·2024-07-15·CVSS 6.7
CVE-2023-37536 [HIGH] Oracle Oracle Essbase Risk Matrix: Essbase Web Platform (Apache Xerces-C++) — CVE-2023-37536
Oracle Oracle Essbase Risk Matrix: Essbase Web Platform (Apache Xerces-C++) vulnerability
CVE: CVE-2023-37536
CVSS: 6.7
Protocol: None
Remote exploit: No
Affected versions: Local
Advisory: cpujul2024 (JUL 2024)
Oracle
Oracle Oracle Fusion Middleware Risk Matrix: Webserver Plugin (Apache Xerces-C++) — CVE-2023-37536
vendor_oracle·2024-04-15·CVSS 8.8
CVE-2023-37536 [HIGH] Oracle Oracle Fusion Middleware Risk Matrix: Webserver Plugin (Apache Xerces-C++) — CVE-2023-37536
Oracle Oracle Fusion Middleware Risk Matrix: Webserver Plugin (Apache Xerces-C++) vulnerability
CVE: CVE-2023-37536
CVSS: 8.8
Protocol: HTTP
Remote exploit: No
Affected versions: Network
Advisory: cpuapr2024 (APR 2024)
Ubuntu
Xerces-C++ vulnerabilities
vendor_ubuntu·2024-01-18·CVSS 8.1
CVE-2018-1311 [HIGH] Xerces-C++ vulnerabilities
Title: Xerces-C++ vulnerabilities
Summary: Several security issues were fixed in Xerces-C++.
It was discovered that Xerces-C++ was not properly handling memory
management operations when parsing XML data containing external DTDs,
which could trigger a use-after-free error. If a user or automated system
were tricked into processing a specially crafted XML document, an attacker
could possibly use this issue to cause a denial of service or execute
arbitrary code. This issue only affected Ubuntu 22.04 LTS. (CVE-2018-1311)
It was discovered that Xerces-C++ was not properly performing bounds
checks when processing XML Schema Definition files, which could lead to an
out-of-bounds access via an HTTP request. If a user or automated system
were tricked into processing a specially crafted XSD file
Oracle
Oracle Oracle Communications Applications Risk Matrix: Security (Apache Xerces-C++) — CVE-2023-37536
vendor_oracle·2024-01-15·CVSS 8.8
CVE-2023-37536 [HIGH] Oracle Oracle Communications Applications Risk Matrix: Security (Apache Xerces-C++) — CVE-2023-37536
Oracle Oracle Communications Applications Risk Matrix: Security (Apache Xerces-C++) vulnerability
CVE: CVE-2023-37536
CVSS: 8.8
Protocol: HTTP
Remote exploit: No
Affected versions: Network
Advisory: cpujan2024 (JAN 2024)
Red Hat
xerces-c: An integer overflow issue that allows remote attackers to cause out-of-bound access via HTTP request
vendor_redhat·2023-10-11·CVSS 8.2
CVE-2023-37536 [HIGH] CWE-190 xerces-c: An integer overflow issue that allows remote attackers to cause out-of-bound access via HTTP request
xerces-c: An integer overflow issue that allows remote attackers to cause out-of-bound access via HTTP request
An integer overflow in xerces-c++ 3.2.3 in BigFix Platform allows remote attackers to cause out-of-bound access via HTTP request.
An integer overflow exists in xerces-c++. This flaw allows an attacker using a specially crafted HTTP request payload to trigger an out-of-bounds read, resulting in a loss of confidentiality, integrity, and availability.
Statement: RHEL-6 is Out of Support Scope.
https://access.redhat.com/articles/4997301
Mitigation: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.
P
Debian
CVE-2023-37536: xerces-c - An integer overflow in xerces-c++ 3.2.3 in BigFix Platform allows remote attacke...
vendor_debian·2023·CVSS 8.2
CVE-2023-37536 [HIGH] CVE-2023-37536: xerces-c - An integer overflow in xerces-c++ 3.2.3 in BigFix Platform allows remote attacke...
An integer overflow in xerces-c++ 3.2.3 in BigFix Platform allows remote attackers to cause out-of-bound access via HTTP request.
Scope: local
bookworm: resolved (fixed in 3.2.4+debian-1)
bullseye: resolved (fixed in 3.2.3+debian-3+deb11u1)
forky: resolved (fixed in 3.2.4+debian-1)
sid: resolved (fixed in 3.2.4+debian-1)
trixie: resolved (fixed in 3.2.4+debian-1)
OSV
xerces-c vulnerabilities
osv·2024-01-18·CVSS 8.1
CVE-2018-1311 [HIGH] xerces-c vulnerabilities
xerces-c vulnerabilities
It was discovered that Xerces-C++ was not properly handling memory
management operations when parsing XML data containing external DTDs,
which could trigger a use-after-free error. If a user or automated system
were tricked into processing a specially crafted XML document, an attacker
could possibly use this issue to cause a denial of service or execute
arbitrary code. This issue only affected Ubuntu 22.04 LTS. (CVE-2018-1311)
It was discovered that Xerces-C++ was not properly performing bounds
checks when processing XML Schema Definition files, which could lead to an
out-of-bounds access via an HTTP request. If a user or automated system
were tricked into processing a specially crafted XSD file, a remote
attacker could possibly use this issue to cause a denial o
GHSA
GHSA-62mq-p983-gjvx: An integer overflow in xerces-c++ 3
ghsa_unreviewed·2023-10-11
CVE-2023-37536 [HIGH] CWE-190 GHSA-62mq-p983-gjvx: An integer overflow in xerces-c++ 3
An integer overflow in xerces-c++ 3.2.3 in BigFix Platform allows remote attackers to cause out-of-bound access via HTTP request.
OSV
CVE-2023-37536: An integer overflow in xerces-c++ 3
osv·2023-10-11·CVSS 8.8
CVE-2023-37536 [HIGH] CVE-2023-37536: An integer overflow in xerces-c++ 3
An integer overflow in xerces-c++ 3.2.3 in BigFix Platform allows remote attackers to cause out-of-bound access via HTTP request.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
https://lists.debian.org/debian-lts-announce/2023/12/msg00027.htmlhttps://lists.fedoraproject.org/archives/list/[email protected]/message/7A6WWL4SWKAVYK6VK5YN7KZP4MZWC7IY/https://lists.fedoraproject.org/archives/list/[email protected]/message/AJYZUBGPVWJ7LEHRCMB5XVADQBNGURXD/https://lists.fedoraproject.org/archives/list/[email protected]/message/DAOSSJ72CUJ535VRWTCVQKUYT2LYR3OM/https://support.hcltechsw.com/csm?id=kb_article&sysparm_article=KB0107791https://lists.debian.org/debian-lts-announce/2023/12/msg00027.htmlhttps://lists.fedoraproject.org/archives/list/[email protected]/message/7A6WWL4SWKAVYK6VK5YN7KZP4MZWC7IY/https://lists.fedoraproject.org/archives/list/[email protected]/message/AJYZUBGPVWJ7LEHRCMB5XVADQBNGURXD/https://lists.fedoraproject.org/archives/list/[email protected]/message/DAOSSJ72CUJ535VRWTCVQKUYT2LYR3OM/https://support.hcltechsw.com/csm?id=kb_article&sysparm_article=KB0107791
2023-10-11
Published