First published: Fri May 03 2024(Updated: )
IBM Aspera Orchestrator 4.0.1 could allow a remote attacker to enumerate usernames due to observable response discrepancies. IBM X-Force ID: 248545.
Credit: psirt@us.ibm.com
Affected Software | Affected Version | How to fix |
---|---|---|
IBM Aspera Orchestrator | <=4.0.1 | |
IBM Aspera Orchestrator | =4.0.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2023-27283 is classified as a medium severity vulnerability due to its potential for username enumeration.
To mitigate CVE-2023-27283, it is recommended to upgrade IBM Aspera Orchestrator to a version beyond 4.0.1.
CVE-2023-27283 could allow remote attackers to enumerate usernames, leading to further exploitation.
CVE-2023-27283 affects IBM Aspera Orchestrator version 4.0.1 and below.
Yes, CVE-2023-27283 involves stored cross-site scripting, which is a web vulnerability.