CVE-2023-37536: HCL BigFix Platform is vulnerable to an integer overflow in xerces-c++ 3.2.3
An integer overflow in xerces-c++ 3.2.3 in BigFix Platform allows remote attackers to cause out-of-bound access via HTTP request.
Other sources
HCL Bigfix is vulnerable to a buffer overflow, caused by an integer overflow in Xerces-c++. By sending a specially crafted HTTP request, a remote authenticated attacker could cause an out-of-bound access to overflow a buffer and execute arbitrary code on the system or cause the application to crash.
— IBM
Affected Software
Event History
Frequently Asked Questions
What is CVE-2023-37536?
CVE-2023-37536 is a vulnerability in the HCL BigFix Platform related to an integer overflow in xerces-c++ 3.2.3.
How does CVE-2023-37536 impact the HCL BigFix Platform?
CVE-2023-37536 allows remote attackers to cause out-of-bound access through HTTP requests.
What is the severity of CVE-2023-37536?
CVE-2023-37536 has a severity rating of 8.2 (high).
Which software versions are affected by CVE-2023-37536?
CVE-2023-37536 affects Apache Xerces-c++ 3.2.3 and HCL BigFix Platform versions 9.0.0 to 9.5.23 and 10.0.0 to 10.0.10.
How can I fix CVE-2023-37536 in the HCL BigFix Platform?
To fix CVE-2023-37536, it is recommended to apply the necessary security patches or updates provided by HCL Technologies.