HCL BigFix OSD Bare Metal Server WebUI is affected by sensitive information disclosure
CVE-2023-37521
5.3MEDIUM
Summary
The HCL BigFix Bare OSD Metal Server WebUI, specifically in versions 311.19 and below, has been identified with a potential vulnerability where sensitive information can be unintentionally exposed in query strings. This loophole may allow attackers to exploit the system by manipulating the query string and deriving confidential data, thereby increasing the risk of malicious activities. Users of the affected versions should take immediate steps to evaluate their configurations and ensure that sensitive data is adequately protected.
Affected Version(s)
HCL BigFix OSD Bare Metal Server WebUI <= 311.19
References
CVSS V3.1
Score:
5.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved