HCL BigFix OSD Bare Metal Server WebUI is affected by sensitive information disclosure
CVE-2023-37521

5.3MEDIUM

Key Information:

Vendor
CVE Published:
16 January 2024

Summary

The HCL BigFix Bare OSD Metal Server WebUI, specifically in versions 311.19 and below, has been identified with a potential vulnerability where sensitive information can be unintentionally exposed in query strings. This loophole may allow attackers to exploit the system by manipulating the query string and deriving confidential data, thereby increasing the risk of malicious activities. Users of the affected versions should take immediate steps to evaluate their configurations and ensure that sensitive data is adequately protected.

Affected Version(s)

HCL BigFix OSD Bare Metal Server WebUI <= 311.19

References

CVSS V3.1

Score:
5.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.