CVE-2023-23949: XSS
An authenticated user can supply malicious HTML and JavaScript code that will be executed in the client browser.
Affected Software
Event History
Frequently Asked Questions
What types of attacks does CVE-2023-23949 expose systems to?
CVE-2023-23949 exposes systems to cross-site scripting (XSS) attacks, allowing attackers to execute malicious scripts in user browsers.
Who is primarily affected by CVE-2023-23949?
CVE-2023-23949 primarily affects users of Broadcom Symantec Identity Governance and Administration and Symantec Identity Manager versions 14.3, 14.4.1, and 14.4.2.
How do I fix CVE-2023-23949?
To fix CVE-2023-23949, update to the latest patched versions of Broadcom Symantec Identity Governance and Administration or Symantec Identity Manager.
What versions of software are impacted by CVE-2023-23949?
CVE-2023-23949 impacts Broadcom Symantec Identity Governance and Administration versions 14.3, 14.4.1, and 14.4.2, as well as Symantec Identity Manager version 14.3 and 14.4.
Is user authentication necessary for exploiting CVE-2023-23949?
Yes, CVE-2023-23949 requires user authentication, meaning an attacker must first gain access as an authenticated user to exploit the vulnerability.