PT-2023-18917 · Ibm · Bigfix Webui Insights
Published
2023-06-23
·
Updated
2024-11-08
·
CVE-2023-23344
CVSS v3.1
6.5
Medium
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
BigFix WebUI Insights site version 14
Description
A permission issue allows an authenticated, unprivileged operator to access an administrator page.
Recommendations
For BigFix WebUI Insights site version 14, update to a version that fixes the permission issue to prevent unprivileged operators from accessing administrator pages.
Fix
Missing Authorization
Incorrect Default Permissions
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Bigfix Webui Insights