CVE-2023-37507

Summary

HCL DevOps Plan is susceptible to an information disclosure that can allow an attacker to focus their attacks based upon the information revealed.

Affected Software

VendorProductVersion RangeStatus
HCLSoftwareDevOps Plan<3.0.05affected

Weaknesses

  • CWE-497: CWE-497 Exposure of sensitive system information to an unauthorized control sphere

ADP Enrichment

CISA ADP Vulnrichment

  • SSVC:
  • Exploitation: none
    • Automatable: no
    • Technical Impact: partial

References