Skip to content

CVE-2023-28019 | HCL BigFix WebUI API

Insufficient validation in Bigfix WebUI API App site version < 14 allows an authenticated WebUI user to issue SQL queries via an unparameterized SQL query. .This CVE has a CVSS3.1 score of 5.5 and a Base Severity of MEDIUM.

InfoDetails
CVE IDCVE-2023-28019
CVE StatePUBLISHED
BaseScore5.5
BaseSeverityMEDIUM
VectorStringCVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:L/I:L/A:L
VersionNA

References for CVE-2023-28019 :
https://support.hcltechsw.com/csm?id=kb_article&sysparm_article=KB0106123

Metric TypeMetric Score
AttackVector(AV)NETWORK
AttackComplexity(AC)LOW
PrivilegesRequired(PR)LOW
UserInteraction(UI)REQUIRED
Scope(S)UNCHANGED
Confidentiality(C)LOW
Availability(A)LOW
Integrity(I)LOW