CVE-2023-45701

HCL Launch could allow a remote attacker to obtain sensitive information when a detailed technical error message is returned in the browser. This information could be used in further attacks against the system.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:hcltechsw:hcl_launch:*:*:*:*:*:*:*:*
cpe:2.3:a:hcltechsw:hcl_launch:*:*:*:*:*:*:*:*
cpe:2.3:a:hcltechsw:hcl_launch:*:*:*:*:*:*:*:*
cpe:2.3:a:hcltechsw:hcl_launch:*:*:*:*:*:*:*:*

History

04 Jan 2024, 20:25

Type Values Removed Values Added
CPE cpe:2.3:a:hcltechsw:hcl_launch:*:*:*:*:*:*:*:*
First Time Hcltechsw
Hcltechsw hcl Launch
CWE CWE-209
References () https://support.hcltechsw.com/csm?id=kb_article&sysparm_article=KB0108645 - () https://support.hcltechsw.com/csm?id=kb_article&sysparm_article=KB0108645 - Vendor Advisory
CVSS v2 : unknown
v3 : 4.3
v2 : unknown
v3 : 6.5

28 Dec 2023, 15:09

Type Values Removed Values Added
Summary
  • (es) HCL Launch podría permitir a un atacante remoto obtener información confidencial cuando se devuelve un mensaje de error técnico detallado en el navegador. Esta información podría usarse en futuros ataques contra el sistema.

28 Dec 2023, 07:15

Type Values Removed Values Added
New CVE

Information

Published : 2023-12-28 07:15

Updated : 2024-01-04 20:25


NVD link : CVE-2023-45701

Mitre link : CVE-2023-45701

CVE.ORG link : CVE-2023-45701


JSON object : View

Products Affected

hcltechsw

  • hcl_launch
CWE
CWE-209

Generation of Error Message Containing Sensitive Information