
Cloud Vulnerability DB
A community-led vulnerabilities database
A cross-site scripting (XSS) vulnerability exists in the Web Reports component of HCL BigFix Platform (CVE-2023-37529). The vulnerability was discovered and disclosed on February 28, 2024, affecting multiple versions of the platform including versions 9.5 through 9.5.23, 10.0 through 10.0.10, and 11.0.0. This vulnerability could potentially allow an attacker to execute malicious JavaScript code into a webpage attempting to retrieve cookie stored information (HCL Advisory).
The vulnerability is classified as a cross-site scripting (XSS) issue that specifically affects the Web Reports component. The CVSS Base Score is 3.0 LOW with a vector of CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:C/C:N/I:L/A:N, indicating a network-attackable vulnerability with high attack complexity, requiring low privileges and user interaction (HCL Advisory).
If successfully exploited, the vulnerability could allow an attacker to execute malicious JavaScript code in a webpage that is attempting to retrieve cookie stored information. This could potentially lead to unauthorized access to sensitive cookie data (HCL Advisory).
The vulnerability requires low privileges and user interaction to exploit, with high attack complexity. The attack vector is network-based, meaning it can be exploited remotely. However, the CVSS scoring indicates that the actual exploitation difficulty is relatively high (HCL Advisory).
HCL has released patches to address this vulnerability. Users of BigFix Platform 11.0.0 should upgrade to Patch 11.0.1, users of version 10.0.10 should upgrade to Patch 10.0.11, and users of version 9.5.23 should upgrade to Patch 9.5.24. These patches can be found and applied through the associated upgrade-patch fixlets in the Console. No other workarounds or mitigations have been provided (HCL Advisory).
The vulnerability was reported to HCLSoftware by security researcher Kajetan Rostojek, along with several other related XSS vulnerabilities in the same product (HCL Advisory).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."