HCL Workload Automation is vulnerable to XML External Entity (XXE) Injection
13Vexday Risk Score
No sign of exploitation. No public exploitation artifact known so far.
ssvc Trackcvss 6.5epss 0.8%
exploitation probability
0.8%top 47% of all CVEs
observed exploitation
nono source reports it
In short
HCL Workload Automation can be tricked into processing malicious XML files that reference external entities, allowing an attacker to steal sensitive data or crash the system by consuming excessive memory.
Technical detail
An XXE injection vulnerability exists in HCL Workload Automation's XML parser that fails to disable external entity resolution. A remote, unauthenticated attacker can send crafted XML payloads to expose sensitive files (information disclosure) or trigger denial of service through billion laughs/XML bomb attacks. No special privileges or user interaction required.
Summary generated and translated by AI from the official description.
HCL Workload Automation is vulnerable to an XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information or consume memory resources.
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Affected products
HCL Software · Workload Automation