SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2023-5830

A vulnerability classified as critical has been found in ColumbiaSoft Document Locator.

CRITICAL 9.8EPSS 60.8%

Does this matter?

EPSS puts the probability of exploitation in the next 30 days at 60.8%, higher than 99% of all known CVEs. Patch or mitigate before the next change window.

Description

A vulnerability classified as critical has been found in ColumbiaSoft Document Locator. This affects an unknown part of the file /api/authentication/login of the component WebTools. The manipulation of the argument Server leads to improper authentication. It is possible to initiate the attack remotely. Upgrading to version 7.2 SP4 and 2021.1 is able to address this issue. It is recommended to upgrade the affected component. The identifier VDB-243729 was assigned to this vulnerability.

CVSS 3.1
9.8 CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS
60.78% probability · 99th percentile
CISA KEV
Not listed
Weakness
CWE-287
Affected
documentlocator/document locator
Source
cna@vuldb.com

References

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.