CVE-2023-27871: IBM Aspera Faspex information disclosure
IBM Aspera Faspex 4.4.2 could allow a remote attacker to obtain sensitive credential information for an external user, using a specially crafted SQL query. IBM X-Force ID: 249613.
Other sources
IBM Aspera Faspex could allow a remote attacker to obtain sensitive credential information for an external user, using a specially crafted SQL query.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the vulnerability ID of this vulnerability?
The vulnerability ID of this vulnerability is CVE-2023-27871.
What is the severity level of CVE-2023-27871?
The severity level of CVE-2023-27871 is high.
What is the affected software for CVE-2023-27871?
The affected software for CVE-2023-27871 is IBM Aspera Faspex version 4.4.2.
How can a remote attacker exploit CVE-2023-27871?
A remote attacker can exploit CVE-2023-27871 by using a specially crafted SQL query to obtain sensitive credential information for an external user.
Is there a patch or fix available for CVE-2023-27871?
Yes, there is a patch available for CVE-2023-27871. Please refer to IBM's support page for more information.