CVE-2023-28937
CVSS 3.1 Score 8.8 of 10 (high)
Details
Summary
CVE-2023-28937: DataSpider Servista versions 4.4 and older contain a critical vulnerability where a hard-coded cryptographic key is used. This key is embedded in ScriptRunner and ScriptRunner for Amazon SQS, making it accessible to all users. An attacker who gains access to a target DataSpider Servista instance and obtains a Launch Settings file of ScriptRunner and/or ScriptRunner for Amazon SQS can decrypt and perform operations with the user privilege. DataSpider Servista and certain OEM products are affected by this issue. For a complete list of affected products and versions, please refer to the references provided.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Affected Vendors
- Saison