BigFix Patch Download Plug-ins are affected by an insecure package which is susceptible to XML injection attacks. This allows an attacker to exploit this vulnerability by injecting malicious XML content, which can lead to various issues including denial of service and unauthorized access.
Metrics
Affected Vendors & Products
References
History
Thu, 23 Jan 2025 15:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Thu, 23 Jan 2025 02:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | BigFix Patch Download Plug-ins are affected by an insecure package which is susceptible to XML injection attacks. This allows an attacker to exploit this vulnerability by injecting malicious XML content, which can lead to various issues including denial of service and unauthorized access. | |
| Title | HCL BigFix Patch Download Plug-ins are affected by an insecure package which is susceptible to XML injection attacks | |
| Weaknesses | CWE-611 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: HCL
Published: 2025-01-23T02:10:02.525Z
Updated: 2025-01-23T14:51:45.463Z
Reserved: 2024-07-29T21:32:05.158Z
Link: CVE-2024-42185
Updated: 2025-01-23T14:51:40.319Z
Status : Received
Published: 2025-01-23T03:15:08.860
Modified: 2025-01-23T03:15:08.860
Link: CVE-2024-42185
No data.