First published: Wed Jul 24 2024(Updated: )
IBM Aspera Orchestrator 4.0.1 is vulnerable to HTTP header injection, caused by improper validation of input by the HOST headers. This could allow an attacker to conduct various attacks against the vulnerable system, including cross-site scripting, cache poisoning or session hijacking. IBM X-Force ID: 248478.
Credit: psirt@us.ibm.com
Affected Software | Affected Version | How to fix |
---|---|---|
IBM Aspera Orchestrator | <=4.0.1 and prior versions | |
IBM Aspera Orchestrator | =4.0.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2023-26289 is considered a critical vulnerability due to its potential for various attacks including cross-site scripting and session hijacking.
To mitigate CVE-2023-26289, you should upgrade IBM Aspera Orchestrator to version 4.0.2 or later, which addresses the HTTP header injection issue.
CVE-2023-26289 allows attackers to perform cross-site scripting, cache poisoning, and session hijacking among other attacks.
CVE-2023-26289 affects IBM Aspera Orchestrator version 4.0.1 and all prior versions.
Organizations using IBM Aspera Orchestrator version 4.0.1 or earlier are affected by CVE-2023-26289.