CVE-2023-37518

Severity CVSS v4.0:
Pending analysis
Type:
CWE-94 Code Injection
Publication date:
30/01/2024
Last modified:
29/05/2025

Description

HCL BigFix ServiceNow is vulnerable to arbitrary code injection. A malicious authorized attacker could inject arbitrary code and execute within the context of the running user.<br />

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:hcltech:bigfix_servicenow_data_flow:*:*:*:*:*:*:*:* 1.3 (excluding)