Início
Tendências
Vulnerabilidades
Notícias
Pesquisadores
Por que dbugs?

Nickolas Britt

Pesquisador dePacketlabs
#34071de 53,633
7.7CVSS total
Vulnerabilidades · 1
PT-2023-26008
7.7
2023-12-21
Ibm · Bigfix Relay · CVE-2023-37520
**Name of the Vulnerable Software and Affected Versions** BigFix Server version 9.5.12.68 **Description** An Unauthenticated Stored Cross-Site Scripting (XSS) issue has been identified, allowing for potential data exfiltration. This issue is located in the Gather Status Report, which is served by the BigFix Relay. **Recommendations** For BigFix Server version 9.5.12.68, consider disabling the Gather Status Report feature until a patch is available to prevent potential exploitation. Restrict access to the BigFix Relay to minimize the risk of data exfiltration. At the moment, there is no information about a newer version that contains a fix for this issue.