CVE-2023-27871

HIGH IN THE WILD

IBM Aspera Faspex < 4.4.2 - SQL Injection

Title source: llm
STIX 2.1

Exploitation Summary

CVE-2023-27871 has been observed exploited in the wild (reported by InTheWild.io).

Description

IBM Aspera Faspex 4.4.2 could allow a remote attacker to obtain sensitive credential information for an external user, using a specially crafted SQL query. IBM X-Force ID: 249613.

References (2)

Core 2
Core References
Patch, Vendor Advisory vendor-advisory
https://www.ibm.com/support/pages/node/6964694

Scores

CVSS v3 7.5
EPSS 0.0033
EPSS Percentile 55.7%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable yes
Technical Impact partial

Details

InTheWild.io 2023-04-05
CWE
CWE-89
Status published
Products (2)
ibm/aspera_faspex 4.4.2 patch_level_1 (2 CPE variants)
ibm/aspera_faspex < 4.4.2
Published Mar 21, 2023
Tracked Since Feb 18, 2026