CVE-2023-45706: HCL BigFix Platform is susceptible to Cross Site Scripting (XSS) and/or Man in the Middle (MITM) attack
Published Mar 28, 2024
·Updated
An administrative user of WebReports may perform a Cross Site Scripting (XSS) and/or Man in the Middle (MITM) exploit through SAML configuration.
Affected Software
4 affected components
HCL BigFix Platform
hcltech Bigfix Platform>=9.5<9.5.24
hcltech Bigfix Platform>=10.0.0<10.0.11
hcltech Bigfix Platform>=11.0.0<=11.0.1
Event History
Mar 28, 2024
CVE Published
via MITRE·02:19 PM
Data Sourced
via MITRE·02:19 PM
DescriptionSeverity
Data Sourced
via NVD·03:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2023-45706?
The severity of CVE-2023-45706 is classified as high due to the potential for Cross Site Scripting (XSS) and Man in the Middle (MITM) exploits.
2
How do I fix CVE-2023-45706?
To fix CVE-2023-45706, administrators should review and update their SAML configurations to eliminate the vulnerability to XSS and MITM attacks.
3
Who is affected by CVE-2023-45706?
CVE-2023-45706 affects users of the HCL BigFix Platform who utilize SAML configurations.
4
What types of attacks can exploit CVE-2023-45706?
CVE-2023-45706 can be exploited via Cross Site Scripting (XSS) and Man in the Middle (MITM) attacks.
5
Is there a patch available for CVE-2023-45706?
Yes, users should check with HCL for any available patches or updates to address CVE-2023-45706.