CVE-2023-37519: HCL BigFix Platform is affected by Unathenticated Stored Cross-Site Scripting (XSS)
Unauthenticated Stored Cross-Site Scripting (XSS) vulnerability. This XSS vulnerability is in the Download Status Report, which is served by the BigFix Server.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2023-37519?
CVE-2023-37519 is classified as an unauthenticated stored cross-site scripting (XSS) vulnerability.
How do I fix CVE-2023-37519?
To fix CVE-2023-37519, ensure you are using an updated version of the HCL BigFix Platform that is not affected by this vulnerability.
Which versions of HCL BigFix Platform are affected by CVE-2023-37519?
CVE-2023-37519 affects HCL BigFix Platform versions between 9.5.0 and 9.5.23, as well as 10.0.0 to 10.0.10, and 11.0.0.
What type of attack does CVE-2023-37519 enable?
CVE-2023-37519 enables attackers to execute unauthenticated stored XSS attacks through the Download Status Report.
How can I test for CVE-2023-37519 on my HCL BigFix Platform?
You can test for CVE-2023-37519 by checking the Download Status Report for any potential XSS payloads that could be stored and executed.