Back to overview

CVE-2023-37507

MEDIUM
6.9
CVSS 4.0
Description
HCL DevOps Plan is susceptible to an information disclosure that can allow an attacker to focus their attacks based upon the information revealed.

Metadata

CVE ID
CVE-2023-37507
State
PUBLISHED
Assigner
HCL
Reserved
2023-07-06 16:11 UTC
Published
2026-07-21 05:00 UTC
Last updated
2026-07-21 05:00 UTC
Primary CWE
CWE-497
CWE-497 Exposure of sensitive system information to an unaut…
Vendor / Product
HCLSoftware / DevOps Plan
Sources
cve.org  ·  NVD

Severity & Metrics

6.9 MEDIUM CVSS 4.0
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N
Affected products (1)
VendorProductPlatformVersions
HCLSoftware DevOps Plan <3.0.05
Weakness (CWE)
CWESourceDescription
CWE-497 cna CWE-497 Exposure of sensitive system information to an unauthorized control sphere
CVSS scores (1)
ScoreSeverityVersionSourceVector
6.9 MEDIUM 4.0 cna CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N
Back to overview