CVE-2023-37529: A cross-site scripting (XSS) vulnerability affects HCL BigFix Platform
A cross-site scripting (XSS) vulnerability in the Web Reports component of HCL BigFix Platform can possibly allow an attacker to execute malicious javascript code into a webpage trying to retrieve cookie stored information. This is not the same vulnerability as identified in CVE-2023-37530.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2023-37529?
CVE-2023-37529 is classified as a high-severity cross-site scripting (XSS) vulnerability.
How do I fix CVE-2023-37529?
To fix CVE-2023-37529, upgrade to the latest version of HCL BigFix Platform that addresses this vulnerability.
Which versions of HCL BigFix Platform are affected by CVE-2023-37529?
CVE-2023-37529 affects HCL BigFix Platform versions 9.5.0 to 9.5.24, 10.0.0 to 10.0.11, and the exact version 11.0.0.
Can CVE-2023-37529 allow unauthorized access to sensitive information?
Yes, CVE-2023-37529 could potentially allow an attacker to execute malicious JavaScript and retrieve sensitive cookie-stored information.
Is CVE-2023-37529 specific to any particular component of HCL BigFix Platform?
CVE-2023-37529 is specifically a vulnerability in the Web Reports component of HCL BigFix Platform.