⚠ Exploited in the wild
Exploitation observed in the wild. Not yet on CISA KEV.

CVE-2023-27874XML External Entity (XXE) Injection in IBM Aspera Faspex

Severity
8.8HIGHNVD
CNA9.9
EPSS
1.1%
top 22.06%
CISA KEV
Not in KEV
Exploit
Exploited in wild
Active exploitation observed
Affected products
Timeline
PublishedMar 21

Description

IBM Aspera Faspex 4.4.2 is vulnerable to an XML external entity injection (XXE) attack when processing XML data. A remote authenticated attacker could exploit this vulnerability to execute arbitrary commands. IBM X-Force ID: 249845.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:HExploitability: 2.8 | Impact: 5.9

Affected Packages2 packages

NVDibm/aspera_faspex4.4.2+1
CVEListV5ibm/aspera_faspex4.4.2

Patches

🔴Vulnerability Details

2
GHSA
GHSA-g822-3v64-2vpm: IBM Aspera Faspex 42023-03-21
CVEList
IBM Aspera Faspex XML external entity injection2023-03-21
CVE-2023-27874 — XML External Entity (XXE) Injection | cvebase