CVE-2023-37522
MEDIUMDescription
HCL BigFix Bare OSD Metal Server WebUI version 311.19 or lower has missing or insecure tags that could allow an attacker to execute a malicious script on the user's browser.
Is your site exposed to CVE-2023-37522?
Run a free security scan — no signup, results in seconds.
CVSS v3.1 Score
Affected Products
| Vendor | Product |
|---|---|
| hcltechsw | bigfix_bare_osd_metal_server_webui |
References
Frequently Asked Questions
What is CVE-2023-37522? +
How severe is CVE-2023-37522? +
What products are affected by CVE-2023-37522? +
How do I check if I'm vulnerable to CVE-2023-37522? +
Related Vulnerabilities
HCL DevOps Deploy / HCL Launch could allow a remote privileged authenticated attacker to execute arbitrary commands on the system …
Security vulnerability in HCL Commerce 9.1.12 and 9.1.13 could allow denial of service, disclosure of user personal data, and performing …
HCL DevOps Deploy / HCL Launch could disclose sensitive configurations and secrets to authenticated users in API responses that could …
HCL DevOps Deploy / HCL Launch does not invalidate session after logout which could allow an authenticated user to impersonate …
HCL DevOps Deploy / HCL Launch could allow unauthorized access to other services or potential exposure of sensitive data due …
HCL Launch stores potentially sensitive information in log files that could be read by a local user with access to …