CVE-2023-32755: e-Excellence U-Office Force - Error Message Leakage
Published Aug 25, 2023
·Updated
e-Excellence U-Office Force generates an error message in webiste service. An unauthenticated remote attacker can obtain partial sensitive system information from error message by sending a crafted command.
Affected Software
1 affected component
Edetw U-office Force=20.0.7668d
Remediation
Information
Update version to 24.50SP1 or later.
Event History
Aug 25, 2023
CVE Published
via MITRE·06:48 AM
Data Sourced
via MITRE·06:48 AM
RemedyDescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2023-32755?
CVE-2023-32755 has been rated as a medium severity vulnerability due to the potential for sensitive information exposure.
2
How do I fix CVE-2023-32755?
To remediate CVE-2023-32755, ensure you upgrade to the latest version of e-Excellence U-Office Force.
3
What information can an attacker gain from CVE-2023-32755?
An unauthenticated remote attacker can obtain partial sensitive system information through error messages generated by the service.
4
Is CVE-2023-32755 exploitable without authentication?
Yes, CVE-2023-32755 can be exploited by unauthenticated remote attackers.
5
Which version of e-Excellence U-Office Force is affected by CVE-2023-32755?
CVE-2023-32755 affects version 20.0.7668d of e-Excellence U-Office Force.