First published: Wed Apr 26 2023(Updated: )
HCL Workload Automation is vulnerable to an XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information or consume memory resources.
Credit: psirt@hcl.com
Affected Software | Affected Version | How to fix |
---|---|---|
Hcltech Workload Automation | =9.4.0 | |
Hcltech Workload Automation | =9.4.0-fix_pack_3 | |
Hcltech Workload Automation | =9.4.0-fix_pack_4 | |
Hcltech Workload Automation | =9.4.0-fix_pack_5 | |
Hcltech Workload Automation | =9.4.0-fix_pack_6 | |
Hcltech Workload Automation | =9.4.0-fix_pack_7 | |
Hcltech Workload Automation | =9.5.0 | |
Hcltech Workload Automation | =9.5.0-fix_pack_1 | |
Hcltech Workload Automation | =9.5.0-fix_pack_2 | |
Hcltech Workload Automation | =9.5.0-fix_pack_3 | |
Hcltech Workload Automation | =9.5.0-fix_pack_4 | |
Hcltech Workload Automation | =9.5.0-fix_pack_5 | |
Hcltech Workload Automation | =9.5.0-fix_pack_6 | |
Hcltech Workload Automation | =10.1.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2023-28009 is high with a CVSS score of 8.1.
CVE-2023-28009 affects HCL Workload Automation by allowing an XML External Entity Injection (XXE) attack, which can lead to exposure of sensitive information or consume memory resources.
Yes, HCL Workload Automation version 9.4.0 is affected by CVE-2023-28009.
To fix CVE-2023-28009 in HCL Workload Automation, you need to upgrade to a fixed version of the software, such as version 9.4.0-fix_pack_3 or later.
You can find more information about CVE-2023-28009 on the HCL Support website at [reference link].