CVE-2023-28937 is a critical vulnerability affecting DataSpider Servista versions 4.4 and earlier, along with some OEM products. It stems from the use of a hard-coded cryptographic key within ScriptRunner and ScriptRunner for Amazon SQS, which are components used to initiate processes on DataSpider Servista. An attacker with access to a target DataSpider Servista instance could obtain a Launch Settings file and leverage this key to perform operations with the encrypted user privileges. This vulnerability carries a CVSS score of 8.8 (High), indicating a significant risk. The attack vector is network-based with low attack complexity, requiring only low privileges and no user interaction. Successful exploitation could lead to high impacts on confidentiality, integrity, and availability. Currently, there is no evidence of active exploitation, and no public exploit code is available in Metasploit, Nuclei, or ExploitDB. Community discussion and media coverage for this CVE are minimal, suggesting a low level of public awareness or attention at this time.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 4.2CPE matchmatch criteria | cpe:2.3:a:saison:dataspider_servista:*:*:*:*:*:*:*:* | ||
4.3CPE matchmatch criteria | cpe:2.3:a:saison:dataspider_servista:4.3:-:*:*:*:*:*:* | ||
4.4CPE matchmatch criteria | cpe:2.3:a:saison:dataspider_servista:4.4:-:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.3 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.