First published: Wed Oct 11 2023(Updated: )
An integer overflow in xerces-c++ 3.2.3 in BigFix Platform allows remote attackers to cause out-of-bound access via HTTP request.
Credit: psirt@hcl.com psirt@hcl.com psirt@hcl.com
Affected Software | Affected Version | How to fix |
---|---|---|
Apache Xerces-c\+\+ | =3.2.3 | |
Hcltech Bigfix Platform | >=9.0.0<9.5.23 | |
Hcltech Bigfix Platform | >=10.0.0<10.0.10 | |
Fedoraproject Fedora | =37 | |
ubuntu/xerces-c | <3.2.0+ | 3.2.0+ |
ubuntu/xerces-c | <3.2.2+ | 3.2.2+ |
ubuntu/xerces-c | <3.2.3+ | 3.2.3+ |
ubuntu/xerces-c | <3.1.1-5.1+ | 3.1.1-5.1+ |
ubuntu/xerces-c | <3.2.4+ | 3.2.4+ |
ubuntu/xerces-c | <3.1.3+ | 3.1.3+ |
debian/xerces-c | <=3.2.2+debian-1+deb10u1 | 3.2.2+debian-1+deb10u2 3.2.3+debian-3+deb11u1 3.2.4+debian-1 3.2.4+debian-1.3 |
redhat/xerces-c | <3.2.4 | 3.2.4 |
IBM Cognos Analytics | <=12.0.0-12.0.3 | |
IBM Cognos Analytics | <=11.2.0-11.2.4 FP4 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2023-37536 is a vulnerability in the HCL BigFix Platform related to an integer overflow in xerces-c++ 3.2.3.
CVE-2023-37536 allows remote attackers to cause out-of-bound access through HTTP requests.
CVE-2023-37536 has a severity rating of 8.2 (high).
CVE-2023-37536 affects Apache Xerces-c++ 3.2.3 and HCL BigFix Platform versions 9.0.0 to 9.5.23 and 10.0.0 to 10.0.10.
To fix CVE-2023-37536, it is recommended to apply the necessary security patches or updates provided by HCL Technologies.