« Volver al listado

CVE-2023-23949

Estado: ModificadaMedia (5.4)—

An authenticated user can supply malicious HTML and JavaScript code that will be executed in the client browser.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (2)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2023-23949",
  "cveTags": [],
  "metrics": {
    "ssvcV203": [
      {
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "ssvcData": {
          "id": "CVE-2023-23949",
          "role": "CISA Coordinator",
          "options": [
            {
              "exploitation": "none"
            },
            {
              "automatable": "no"
            },
            {
              "technicalImpact": "total"
            }
          ],
          "version": "2.0.3",
          "timestamp": "2025-04-02T14:35:51.739624Z"
        }
      }
    ],
    "cvssMetricV31": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "scope": "CHANGED",
          "version": "3.1",
          "baseScore": 5.4,
          "attackVector": "NETWORK",
          "baseSeverity": "MEDIUM",
          "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N",
          "integrityImpact": "LOW",
          "userInteraction": "REQUIRED",
          "attackComplexity": "LOW",
          "availabilityImpact": "NONE",
          "privilegesRequired": "LOW",
          "confidentialityImpact": "LOW"
        },
        "impactScore": 2.7,
        "exploitabilityScore": 2.3
      },
      {
        "type": "Secondary",
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 8.1,
          "attackVector": "NETWORK",
          "baseSeverity": "HIGH",
          "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N",
          "integrityImpact": "HIGH",
          "userInteraction": "REQUIRED",
          "attackComplexity": "LOW",
          "availabilityImpact": "NONE",
          "privilegesRequired": "NONE",
          "confidentialityImpact": "HIGH"
        },
        "impactScore": 5.2,
        "exploitabilityScore": 2.8
      }
    ]
  },
  "affected": [
    {
      "source": "secure@symantec.com",
      "affectedData": [
        {
          "vendor": "n/a",
          "product": "Symantec Identity Management And Governance",
          "versions": [
            {
              "status": "affected",
              "version": "14.3, 14.4.1, 14.4.2"
            }
          ]
        }
      ]
    }
  ],
  "published": "2023-01-26T21:18:15.340",
  "references": [
    {
      "url": "https://support.broadcom.com/external/content/SecurityAdvisories/0/21174",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "secure@symantec.com"
    },
    {
      "url": "https://support.broadcom.com/external/content/SecurityAdvisories/0/21174",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "CWE-79"
        }
      ]
    },
    {
      "type": "Secondary",
      "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
      "description": [
        {
          "lang": "en",
          "value": "CWE-779"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "An authenticated user can supply malicious HTML and JavaScript code that will be executed in the client browser."
    },
    {
      "lang": "es",
      "value": "Un usuario autenticado puede proporcionar código HTML y JavaScript malicioso que se ejecutará en el navegador del cliente."
    }
  ],
  "lastModified": "2026-06-17T05:38:21.203",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:broadcom:symantec_identity_governance_and_administration:14.3:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "F02FD4DC-D8DF-4665-A0FC-0B62FA66939E"
            },
            {
              "criteria": "cpe:2.3:a:broadcom:symantec_identity_governance_and_administration:14.4.1:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "23689A8F-BF69-411B-93C1-584E3251B55E"
            },
            {
              "criteria": "cpe:2.3:a:broadcom:symantec_identity_governance_and_administration:14.4.2:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "AAE61084-5A83-466E-96CA-46E84645AC2B"
            },
            {
              "criteria": "cpe:2.3:a:broadcom:symantec_identity_manager:14.3:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "25ABF24A-6352-469C-928E-67A4BEDB579C"
            },
            {
              "criteria": "cpe:2.3:a:broadcom:symantec_identity_manager:14.4:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "FF8B308A-3E78-4E0D-9148-91B39BAF8845"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "secure@symantec.com"
}