CVE-2023-27875: IBM Aspera Faspex improper access controls
Published Mar 16, 2023
·Updated
IBM Aspera Faspex 5.0.4 could allow a user to change other user's credentials due to improper access controls. IBM X-Force ID: 249847.
Affected Software
6 affected components
IBM Aspera Faspex=5.0.4
Linux Linux Kernel
Microsoft Windows
All of the following
IBM Aspera Faspex=5.0.4
Any of the following
Linux Linux Kernel
Microsoft Windows
Remediation
Patch Available
Event History
Mar 16, 2023
CVE Published
via MITRE·12:37 PM
Data Sourced
via MITRE·12:37 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·01:15 PM
RemedyDescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is CVE-2023-27875?
CVE-2023-27875 is a vulnerability in IBM Aspera Faspex 5.0.4 that could allow a user to change other user's credentials due to improper access controls.
2
What is the severity of CVE-2023-27875?
The severity of CVE-2023-27875 is high with a CVSS score of 7.5.
3
How does CVE-2023-27875 affect IBM Aspera Faspex?
CVE-2023-27875 affects IBM Aspera Faspex 5.0.4 by allowing a user to change other user's credentials.
4
Is Linux Linux kernel affected by CVE-2023-27875?
No, Linux Linux kernel is not affected by CVE-2023-27875.
5
Is Microsoft Windows affected by CVE-2023-27875?
No, Microsoft Windows is not affected by CVE-2023-27875.
6
Where can I find more information about CVE-2023-27875?
You can find more information about CVE-2023-27875 at the IBM X-Force ID website: https://exchange.xforce.ibmcloud.com/vulnerabilities/249847