Vulnerability Details CVE-2023-27874
IBM Aspera Faspex 4.4.2 is vulnerable to an XML external entity injection (XXE) attack when processing XML data. A remote authenticated attacker could exploit this vulnerability to execute arbitrary commands. IBM X-Force ID: 249845.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.001
EPSS Ranking 34.8%
CVSS Severity
CVSS v3 Score 9.9
Products affected by CVE-2023-27874
-
cpe:2.3:a:ibm:aspera_faspex:-
-
cpe:2.3:a:ibm:aspera_faspex:4.4.1
-
cpe:2.3:a:ibm:aspera_faspex:4.4.2
-
cpe:2.3:o:linux:linux_kernel:-