CVE-2023-27873: IBM Aspera Faspex information disclosure
IBM Aspera Faspex 4.4.2 could allow a remote authenticated attacker to obtain sensitive credential information using specially crafted XML input. IBM X-Force ID: 249654.
Other sources
IBM Aspera Faspex could allow a remote authenticated attacker to obtain sensitive credential information using specially crafted XML input.
— IBM
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the vulnerability ID?
The vulnerability ID is CVE-2023-27873.
What is the title of the vulnerability?
The title of the vulnerability is 'IBM Aspera Faspex could allow a remote authenticated attacker to obtain sensitive credential information'.
What is the severity of CVE-2023-27873?
The severity of CVE-2023-27873 is medium.
Which software versions are affected by CVE-2023-27873?
IBM Aspera Faspex versions 4.4.2, 4.4.2-patch_level_1, and 4.4.2-patch_level_2 are affected by CVE-2023-27873.
How can a remote authenticated attacker exploit CVE-2023-27873?
A remote authenticated attacker can exploit CVE-2023-27873 by using specially crafted XML input to obtain sensitive credential information.