CVE-2023-37536: Apache Xerces-C++

High severity, CVSS 8.8. EPSS: 1.4% chance of exploitation in the next 30 days.

An integer overflow in xerces-c++ 3.2.3 in BigFix Platform allows remote attackers to cause out-of-bound access via HTTP request.

Affected products

  • Apache Xerces-C++: version 3.2.3 only
  • Fedoraproject Fedora: version 37 only
  • Hcltech Bigfix Platform: from 9.0.0, before 9.5.23 (fixed in 9.5.23); from 10.0.0, before 10.0.10 (fixed in 10.0.10)

Published 2023-10-11. Last modified 2026-06-17.