PT-2023-18916 · Hcl · Hcl Bigfix Osd Bare Metal Server

CVE-2023-23343

·

Published

2023-06-22

·

Updated

2023-07-03

CVSS v3.1

6.1

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions HCL BigFix OSD Bare Metal Server versions 311.12 and earlier
Description A clickjacking issue allows an attacker to use transparent or opaque layers to trick a user into clicking on a button or link on another page, resulting in a redirect to an attacker-controlled domain.
Recommendations For HCL BigFix OSD Bare Metal Server versions 311.12 and earlier, update to a version higher than 311.12 to resolve the issue. As a temporary workaround, consider implementing additional validation on user interactions to minimize the risk of clickjacking attacks.

Fix

Clickjacking

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2023-23343

Affected Products

Hcl Bigfix Osd Bare Metal Server