CVE-2023-23951: XSS
Ability to enumerate the Oracle LDAP attributes for the current user by modifying the query used by the application
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2023-23951?
CVE-2023-23951 is classified as a high severity vulnerability.
How do I fix CVE-2023-23951?
To fix CVE-2023-23951, upgrade to the latest version of the affected Broadcom Symantec Identity Governance and Administration or Identity Manager software.
What is the impact of CVE-2023-23951?
The impact of CVE-2023-23951 allows attackers to enumerate LDAP attributes for the current user, potentially exposing sensitive information.
Which versions are affected by CVE-2023-23951?
CVE-2023-23951 affects Broadcom Symantec Identity Governance and Administration versions 14.3, 14.4.1, and 14.4.2 and Symantec Identity Manager versions 14.3 and 14.4.
Can CVE-2023-23951 be exploited remotely?
Yes, CVE-2023-23951 can be exploited remotely by attackers who can manipulate queries used by the affected application.