CVE-2024-23551
HCL BigFix Compliance is potentially affected by Oracle database credentials stored at endpoint
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
Database scanning using username and password stores the credentials in plaintext or encoded format within files at the endpoint. This has been identified as a significant security risk. This will lead to exposure of sensitive information for unauthorized access, potentially leading to severe consequences such as data breaches, unauthorized data manipulation, and compromised system integrity.
El escaneo de la base de datos mediante nombre de usuario y contraseña almacena las credenciales en texto sin formato o en formato codificado dentro de archivos en el endpoint. Esto ha sido identificado como un riesgo de seguridad importante. Esto dará lugar a la exposición de información confidencial para acceso no autorizado, lo que podría tener consecuencias graves, como violaciones de datos, manipulación de datos no autorizada y compromiso de la integridad del sistema.
Database scanning using username and password stores the credentials in plaintext or encoded format within files at the endpoint. This has been identified as a significant security risk. This will lead to exposure of sensitive information for unauthorized access, potentially leading to severe consequences such as data breaches, unauthorized data manipulation, and compromised system integrity.
CVSS Scores
SSVC
- Decision:Track*
Timeline
- 2024-01-18 CVE Reserved
- 2024-05-07 CVE Published
- 2024-08-01 CVE Updated
- 2025-06-16 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-522: Insufficiently Protected Credentials
CAPEC
References (1)
URL | Date | SRC |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Hcltech Search vendor "Hcltech" | Bigfix Compliance Search vendor "Hcltech" for product "Bigfix Compliance" | * | - |
Affected
|