Improper access control in SOAR QRadar Plugin App - CVE-2023-38263
Published: February 1, 2024
Vulnerability identifier: #VU85983
CSH Severity: Low
CVSS v4: 5.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2023-38263
CWE-ID: CWE-284
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote user to gain unauthorized access to otherwise restricted functionality.
The vulnerability exists due to improper access restrictions. A remote user can bypass implemented security restrictions and gain unauthorized access to the application.
Affected software
SOAR QRadar Plugin App
Juniper Secure Analytics (JSA)
Juniper Secure Analytics (JSA)
How to mitigate CVE-2023-38263
Install updates from vendor's website.
SOAR QRadar Plugin App - update to 5.3.1
Juniper Secure Analytics (JSA) - update to 7.5.0 UP7 IF04
Juniper Secure Analytics (JSA) - update to 7.5.0 UP7 IF04