CVE-2023-27874: IBM Aspera Faspex XML external entity injection
IBM Aspera Faspex 4.4.2 is vulnerable to an XML external entity injection (XXE) attack when processing XML data. A remote authenticated attacker could exploit this vulnerability to execute arbitrary commands. IBM X-Force ID: 249845.
Other sources
IBM Aspera is vulnerable to an XML external entity injection (XXE) attack when processing XML data. A remote authenticated attacker could exploit this vulnerability to execute arbitrary commands.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2023-27874?
The severity of CVE-2023-27874 is critical with a severity value of 9.9.
How does CVE-2023-27874 affect IBM Aspera Faspex?
CVE-2023-27874 affects IBM Aspera Faspex version 4.4.2 and patch levels 4.4.2-patch_level_1 and 4.4.2-patch_level_2.
What is an XML external entity injection (XXE) attack?
An XML external entity injection (XXE) attack is a vulnerability that allows an attacker to exploit the processing of XML data to execute arbitrary commands.
How can a remote authenticated attacker exploit CVE-2023-27874?
A remote authenticated attacker can exploit CVE-2023-27874 to execute arbitrary commands.
Where can I find more information about CVE-2023-27874?
You can find more information about CVE-2023-27874 at the following references: [IBM X-Force ID: 249845](https://exchange.xforce.ibmcloud.com/vulnerabilities/249845) and [IBM support page](https://www.ibm.com/support/pages/node/6964694).