DECEMBER 2023

Potential sensitive information disclosure CVE-2023-49961

SUMMARY

A vulnerability has been discovered in the WALLIX products that may allow an attacker to access sensitive information. The attacker could use this vulnerability to gain illegitimate accesses.

WALLIX recommends to immediately apply the published fixes, or before it is applied, the workaround described below.

Affected Products

All supported versions of WALLIX Bastion and Access Manager as an appliance.

Workarounds

The following article of our knowledge base provides you with the mitigation procedure.

Fixed Software

Hotfixes versions and patches are available on our download portal:

Exploitation and Public Annoncements

WALLIX is not aware of any public announcements or malicious use of the vulnerability that is described in this advisory.

However, it is recommended to look for any abnormal activity on the WALLIX Bastions and WALLIX Access Manager. It is recommended also to ensure that Bastion and Access Manager firewall are enabled.