CVE-2023-23950: XSS
Published Jan 24, 2023
·Updated
User’s supplied input (usually a CRLF sequence) can be used to split a returning response into two responses.
Affected Software
5 affected components
Broadcom Symantec Identity Governance And Administration=14.3
Broadcom Symantec Identity Governance And Administration=14.4.1
Broadcom Symantec Identity Governance And Administration=14.4.2
Broadcom Symantec Identity Manager=14.3
Broadcom Symantec Identity Manager=14.4
Event History
Jan 24, 2023
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
DescriptionWeakness
Frequently Asked Questions
1
What is the severity of CVE-2023-23950?
CVE-2023-23950 is classified as a medium-severity vulnerability.
2
How do I fix CVE-2023-23950?
To fix CVE-2023-23950, update to the latest versions of affected Broadcom products as provided in their security advisories.
3
What is the impact of CVE-2023-23950?
CVE-2023-23950 can allow an attacker to manipulate HTTP responses by exploiting user-supplied input.
4
Which software versions are affected by CVE-2023-23950?
CVE-2023-23950 affects Broadcom Symantec Identity Governance and Administration versions 14.3, 14.4.1, and 14.4.2, as well as Symantec Identity Manager versions 14.3 and 14.4.
5
Is CVE-2023-23950 remotely exploitable?
Yes, CVE-2023-23950 is remotely exploitable if the affected software is exposed to the internet.