CVE-2023-28937

CVSS 3.1 Score 8.8 of 10 (high)

Details

Published Jun 1, 2023
Updated: Jan 9, 2025
CWE ID 798

Summary

CVE-2023-28937: DataSpider Servista versions 4.4 and older contain a critical vulnerability where a hard-coded cryptographic key is used. This key is embedded in ScriptRunner and ScriptRunner for Amazon SQS, making it accessible to all users. An attacker who gains access to a target DataSpider Servista instance and obtains a Launch Settings file of ScriptRunner and/or ScriptRunner for Amazon SQS can decrypt and perform operations with the user privilege. DataSpider Servista and certain OEM products are affected by this issue. For a complete list of affected products and versions, please refer to the references provided.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share