Lucene search

K
cveHCLCVE-2023-37497
HistoryAug 03, 2023 - 10:15 p.m.

CVE-2023-37497

2023-08-0322:15:12
CWE-611
HCL
web.nvd.nist.gov
2465
unica
api
xxe
xml
security
nvd
cve-2023-37497

CVSS3

8.8

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

AI Score

8.5

Confidence

High

EPSS

0.001

Percentile

38.5%

The Unica application exposes an API which accepts arbitrary XML input. By manipulating the given XML, an authenticated attacker with certain rights can successfully perform XML External Entity attacks (XXE) against the backend service.

Affected configurations

Nvd
Node
hcltechunicaRange<11.1.0.6
OR
hcltechunicaRange12.012.1.1
VendorProductVersionCPE
hcltechunica*cpe:2.3:a:hcltech:unica:*:*:*:*:*:*:*:*

CNA Affected

[
  {
    "defaultStatus": "unaffected",
    "product": "HCL Unica Platform",
    "vendor": "HCL Software",
    "versions": [
      {
        "status": "affected",
        "version": "< 11.1.0.6, <12.1.1"
      }
    ]
  }
]

CVSS3

8.8

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

AI Score

8.5

Confidence

High

EPSS

0.001

Percentile

38.5%

Related for CVE-2023-37497