PT-2024-19931 · Hcl · Hcl Bigfix Inventory Server

Published

2024-04-03

·

Updated

2024-07-12

·

CVE-2024-23540

CVSS v3.1

5.3

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
Name of the Vulnerable Software and Affected Versions HCL BigFix Inventory server (affected versions not specified)
Description The issue allows an attacker to perform path traversal, enabling them to read internal application files from the server. This is due to the server not properly restricting the served static files.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Path traversal

Weakness Enumeration

Related Identifiers

CVE-2024-23540

Affected Products

Hcl Bigfix Inventory Server