Lucene search

K
vulnrichmentHCLVULNRICHMENT:CVE-2023-37536
HistoryOct 11, 2023 - 6:46 a.m.

CVE-2023-37536 HCL BigFix Platform is vulnerable to an integer overflow in xerces-c++ 3.2.3

2023-10-1106:46:01
HCL
github.com
5
hcl bigfix platform
integer overflow
xerces-c++ 3.2.3
remote attackers
out-of-bound access
http request

CVSS3

8.2

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

REQUIRED

Scope

CHANGED

Confidentiality Impact

LOW

Integrity Impact

LOW

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:H

AI Score

7.1

Confidence

High

SSVC

Exploitation

none

Automatable

no

Technical Impact

total

An integer overflow in xerces-c++ 3.2.3 in BigFix Platform allows remote attackers to cause out-of-bound access via HTTP request.

ADP Affected

[
  {
    "cpes": [
      "cpe:2.3:a:hcltech:bigfix_platform:10:*:*:*:*:*:*:*",
      "cpe:2.3:a:hcltech:bigfix_platform:9.5:*:*:*:*:*:*:*"
    ],
    "vendor": "hcltech",
    "product": "bigfix_platform",
    "versions": [
      {
        "status": "affected",
        "version": "10",
        "versionType": "semver",
        "lessThanOrEqual": "9.5.22"
      },
      {
        "status": "affected",
        "version": "9.5",
        "versionType": "semver",
        "lessThanOrEqual": "10.0.9"
      }
    ],
    "defaultStatus": "unknown"
  },
  {
    "cpes": [
      "cpe:2.3:o:fedoraproject:fedora:37:*:*:*:*:*:*:*",
      "cpe:2.3:o:fedoraproject:fedora:38:*:*:*:*:*:*:*",
      "cpe:2.3:o:fedoraproject:fedora:39:*:*:*:*:*:*:*"
    ],
    "vendor": "fedoraproject",
    "product": "fedora",
    "versions": [
      {
        "status": "affected",
        "version": "37"
      },
      {
        "status": "affected",
        "version": "38"
      },
      {
        "status": "affected",
        "version": "39"
      }
    ],
    "defaultStatus": "unknown"
  },
  {
    "cpes": [
      "cpe:2.3:a:apache:xerces-c\\+\\+:3.2.2:*:*:*:*:*:*:*"
    ],
    "vendor": "apache",
    "product": "xerces-c\\+\\+",
    "versions": [
      {
        "status": "affected",
        "version": "3.2.2"
      }
    ],
    "defaultStatus": "unknown"
  }
]

CVSS3

8.2

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

REQUIRED

Scope

CHANGED

Confidentiality Impact

LOW

Integrity Impact

LOW

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:H

AI Score

7.1

Confidence

High

SSVC

Exploitation

none

Automatable

no

Technical Impact

total