CVE-2023-28009: HCL Workload Automation is vulnerable to XML External Entity (XXE) Injection
HCL Workload Automation is vulnerable to an XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information or consume memory resources.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2023-28009?
The severity of CVE-2023-28009 is high with a CVSS score of 8.1.
How does CVE-2023-28009 affect HCL Workload Automation?
CVE-2023-28009 affects HCL Workload Automation by allowing an XML External Entity Injection (XXE) attack, which can lead to exposure of sensitive information or consume memory resources.
Is HCL Workload Automation version 9.4.0 affected by CVE-2023-28009?
Yes, HCL Workload Automation version 9.4.0 is affected by CVE-2023-28009.
How can I fix CVE-2023-28009 in HCL Workload Automation?
To fix CVE-2023-28009 in HCL Workload Automation, you need to upgrade to a fixed version of the software, such as version 9.4.0-fix_pack_3 or later.
Where can I find more information about CVE-2023-28009?
You can find more information about CVE-2023-28009 on the HCL Support website at [reference link].