PT-2024-12627 · Hcl · Hcl Bigfix Bare Osd Metal Server Webui

CVE-2023-37521

·

Published

2024-01-16

·

Updated

2024-10-29

CVSS v3.1

5.3

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions HCL BigFix Bare OSD Metal Server WebUI versions 311.19 or lower
Description The issue concerns the inclusion of sensitive information in a query string, potentially allowing an attacker to execute a malicious attack.
Recommendations For HCL BigFix Bare OSD Metal Server WebUI versions 311.19 or lower, consider updating to a version higher than 311.19 to resolve the issue. As a temporary workaround, restrict access to sensitive query strings to minimize the risk of exploitation.

Fix

Insecure Storage of Sensitive Information

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2023-37521

Affected Products

Hcl Bigfix Bare Osd Metal Server Webui