PT-2023-18916 · Hcl · Hcl Bigfix Osd Bare Metal Server

Published

2023-06-22

·

Updated

2023-07-03

·

CVE-2023-23343

CVSS v3.1

6.1

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions HCL BigFix OSD Bare Metal Server versions 311.12 and earlier
Description A clickjacking issue allows an attacker to use transparent or opaque layers to trick a user into clicking on a button or link on another page, resulting in a redirect to an attacker-controlled domain.
Recommendations For HCL BigFix OSD Bare Metal Server versions 311.12 and earlier, update to a version higher than 311.12 to resolve the issue. As a temporary workaround, consider implementing additional validation on user interactions to minimize the risk of clickjacking attacks.

Fix

Clickjacking

Weakness Enumeration

Related Identifiers

CVE-2023-23343

Affected Products

Hcl Bigfix Osd Bare Metal Server