← Back

CVE-2023-37497

nvd nist
Published: Aug 3, 2023Modified: Jun 17, 2026

JSON object

Loading...
8.8
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Exploitability: 2.8 / Impact: 5.9
Source: NVD

Description

The Unica application exposes an API which accepts arbitrary XML input. By manipulating the given XML, an authenticated attacker with certain rights can successfully perform XML External Entity attacks (XXE) against the backend service.

Affected (2)

Products: Hcltech: Unica
1 product
Unica
Configuration A
2 vulnerable
Vulnerable SoftwareAffected Versions
Hcltech
Before 11.1.0.6
From 12.0 to 12.1.1

References (2)

Timeline

No history available yet.