An XML External Entity (XXE) Injection Vulnerability affects HCL Unica Platform
CVE-2023-37497
8.1HIGH
What is CVE-2023-37497?
The HCL Unica application features an application programming interface (API) that unintentionally permits the processing of arbitrary XML input. By cleverly crafting and submitting XML payloads, an authenticated attacker with appropriate privileges can exploit this vulnerability to execute XML External Entity (XXE) attacks, leading to potential exposure of sensitive data, server-side request forgery (SSRF), and other security risks to the backend services.
Affected Version(s)
HCL Unica Platform < 11.1.0.6, <12.1.1