CVE-2023-37497

Severity CVSS v4.0:
Pending analysis
Type:
CWE-611 Improper Restriction of XML External Entity Reference ('XXE')
Publication date:
03/08/2023
Last modified:
08/08/2023

Description

The Unica application exposes an API which accepts arbitrary XML input. By manipulating the given XML, an authenticated attacker with certain rights can successfully perform XML External Entity attacks (XXE) against the backend service.<br />

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:hcltech:unica:*:*:*:*:*:*:*:* 11.1.0.6 (excluding)
cpe:2.3:a:hcltech:unica:*:*:*:*:*:*:*:* 12.0 (including) 12.1.1 (excluding)