← Back to browse · API

CVE-2023-27874

Severity
CRITICAL
CVSS
9.9
EPSS
0.01343
Risk score
40.07
CISA KEV
No
PoC
No
Published
2023-03-21
Modified
2025-02-26
First seen
2026-08-07
Aliases
EUVD-2023-31609, GHSA-G822-3V64-2VPM
Products
IBM:Aspera Faspex 4.4.2
Sources
euvd EUVD-2023-31609

Description

IBM Aspera Faspex 4.4.2 is vulnerable to an XML external entity injection (XXE) attack when processing XML data. A remote authenticated attacker could exploit this vulnerability to execute arbitrary commands. IBM X-Force ID: 249845.

References