CVE-2023-28008: HCL Workload Automation is vulnerable to XML External Entity (XXE) Injection
HCL Workload Automation 9.4, 9.5, and 10.1 are vulnerable to an XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information or consume memory resources.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2023-28008?
CVE-2023-28008 is a vulnerability in HCL Workload Automation 9.4, 9.5, and 10.1 that allows for XML External Entity Injection (XXE) attacks.
What is the severity of CVE-2023-28008?
CVE-2023-28008 has a severity rating of 8.1 (High).
How can a remote attacker exploit the CVE-2023-28008 vulnerability?
A remote attacker can exploit the CVE-2023-28008 vulnerability by sending specially crafted XML data to the affected HCL Workload Automation instances, leading to XML External Entity Injection (XXE) attacks.
Which versions of HCL Workload Automation are affected by CVE-2023-28008?
HCL Workload Automation versions 9.4, 9.5, and 10.1 are affected by CVE-2023-28008.
How can I fix the CVE-2023-28008 vulnerability?
To fix the CVE-2023-28008 vulnerability, it is recommended to apply the necessary security patches or updates provided by HCL Technologies.