First published: Thu Jul 13 2023(Updated: )
A malicious file could be uploaded into a System Manager User Import Function resulting in a hijacked session.
Credit: cybersecurity@bd.com cybersecurity@bd.com
Affected Software | Affected Version | How to fix |
---|---|---|
BD Alaris Systems Manager | <=12.3 |
BD recommends customers update to the BD Alarisâ„¢ System v12.3, where available based on regulatory authorization. Customers who require software updates should contact their BD Account Executive to assist with scheduling the remediation.
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID for this vulnerability is CVE-2023-30563.
The title of this vulnerability is Stored Cross-Site Scripting on User Import Functionality.
The description of this vulnerability is that a malicious file could be uploaded into a System Manager User Import Function resulting in a hijacked session.
The affected software for this vulnerability is BD Alaris Systems Manager version 12.3.
The severity of this vulnerability is high with a CVSS score of 8.2.
Yes, you can find more information about this vulnerability [here](https://www.bd.com/en-us/about-bd/cybersecurity/bulletin/bd-alaris-system-with-guardrails-suite-mx).
The CWE ID for this vulnerability is CWE-79.