PT-2024-12627 · Hcl · Hcl Bigfix Bare Osd Metal Server Webui

Published

2024-01-16

·

Updated

2024-10-29

·

CVE-2023-37521

CVSS v3.1

5.3

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions HCL BigFix Bare OSD Metal Server WebUI versions 311.19 or lower
Description The issue concerns the inclusion of sensitive information in a query string, potentially allowing an attacker to execute a malicious attack.
Recommendations For HCL BigFix Bare OSD Metal Server WebUI versions 311.19 or lower, consider updating to a version higher than 311.19 to resolve the issue. As a temporary workaround, restrict access to sensitive query strings to minimize the risk of exploitation.

Fix

Insecure Storage of Sensitive Information

Weakness Enumeration

Related Identifiers

CVE-2023-37521

Affected Products

Hcl Bigfix Bare Osd Metal Server Webui