CVE-2023-27876
published 2023-04-07CVE-2023-27876: IBM TRIRIGA 4.0 is vulnerable to an XML external entity injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to…
PriorityP341high7.1CVSS 3.1
AVNACLPRLUINSUCHINAL
EPSS
0.94%
56.8th percentile
IBM TRIRIGA 4.0 is vulnerable to an XML external entity injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information or consume memory resources. IBM X-Force ID: 249975.
Affected
1 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| ibm | tririga_application_platform | — | — |
CVSS provenance
nvdv3.17.1HIGHCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:L
cisa8.1HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-9mrh-vv7h-7mx2: IBM TRIRIGA 4
ghsa_unreviewed·2023-04-07
CVE-2023-27876 [HIGH] CWE-611 GHSA-9mrh-vv7h-7mx2: IBM TRIRIGA 4
IBM TRIRIGA 4.0 is vulnerable to an XML external entity injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information or consume memory resources. IBM X-Force ID: 249975.
CISA
Veritas Backup Exec Agent File Access Vulnerability
cisa·2023-04-07·CVSS 8.1
CVE-2021-27876 [HIGH] CWE-287 Veritas Backup Exec Agent File Access Vulnerability
Vulnerability: Veritas Backup Exec Agent File Access Vulnerability
Affected: Veritas Backup Exec Agent
Veritas Backup Exec (BE) Agent contains a file access vulnerability that could allow an attacker to specially craft input parameters on a data management protocol command to access files on the BE Agent machine.
Required Action: Apply updates per vendor instructions.
Notes: https://www.veritas.com/support/en_US/security/VTS21-001; https://nvd.nist.gov/vuln/detail/CVE-2021-27876
Remediation Due Date: 2023-04-28
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2023-04-07
Published