5.3
CVE-2023-37521
- EPSS 0.22%
- Veröffentlicht 16.01.2024 16:15:10
- Zuletzt bearbeitet 21.11.2024 08:11:51
- Quelle psirt@hcl.com
- CVE-Watchlists
- Unerledigt
HCL BigFix OSD Bare Metal Server WebUI is affected by sensitive information disclosure
HCL BigFix Bare OSD Metal Server WebUI version 311.19 or lower can sometimes include sensitive information in a query string which could allow an attacker to execute a malicious attack.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Hcltechsw ≫ Bigfix Bare Osd Metal Server Webui Version < 311.28
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.22% | 0.445 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| nvd@nist.gov | 5.3 | 3.9 | 1.4 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
|
| psirt@hcl.com | 2.3 | 0.8 | 1.4 |
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:L/I:N/A:N
|
CWE-922 Insecure Storage of Sensitive Information
The product stores sensitive information without properly limiting read or write access by unauthorized actors.