HCL Workload Automation is vulnerable to XML External Entity (XXE) Injection
CVE-2023-28009
6.5MEDIUM
What is CVE-2023-28009?
HCL Workload Automation is susceptible to an XML External Entity Injection attack, which occurs during the processing of XML data. This vulnerability allows a remote attacker to manipulate XML input to extract sensitive information or exploit system resources, leading to potential information exposure or denial of service.
Affected Version(s)
Workload Automation <=9.5.0.6, 10.1.0.0