Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-g822-3v64-2vpm

Опубликовано: 21 мар. 2023
Источник: github
Github: Не прошло ревью
CVSS3: 8.8

Описание

IBM Aspera Faspex 4.4.2 is vulnerable to an XML external entity injection (XXE) attack when processing XML data. A remote authenticated attacker could exploit this vulnerability to execute arbitrary commands. IBM X-Force ID: 249845.

IBM Aspera Faspex 4.4.2 is vulnerable to an XML external entity injection (XXE) attack when processing XML data. A remote authenticated attacker could exploit this vulnerability to execute arbitrary commands. IBM X-Force ID: 249845.

EPSS

Процентиль: 44%
0.00218
Низкий

8.8 High

CVSS3

Дефекты

CWE-611

Связанные уязвимости

CVSS3: 9.9
nvd
почти 3 года назад

IBM Aspera Faspex 4.4.2 is vulnerable to an XML external entity injection (XXE) attack when processing XML data. A remote authenticated attacker could exploit this vulnerability to execute arbitrary commands. IBM X-Force ID: 249845.

EPSS

Процентиль: 44%
0.00218
Низкий

8.8 High

CVSS3

Дефекты

CWE-611