IBM Aspera Console XPath injection
Published Apr 14, 2025
4.3
MEDIUMCVSS 3.1
EPSS 0.30%
Description
IBM Aspera Console 3.4.0 through 3.4.4
is vulnerable to an XPath injection vulnerability, which could allow an authenticated attacker to exfiltrate sensitive application data and/or determine the structure of the XML document.
Affected products
-
- Version 3.4.0StatusaffectedConstraints<=3.4.4
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | ||||||
|---|---|---|---|---|---|---|---|---|---|
| IBM | Aspera Console | unaffected |
|
- ≥ 3.4.0 · ≤ 3.4.4
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
Vendor solution
It is recommended that customers upgrade to the latest version of IBM Aspera Console:
Product(s)Fixing VRMPlatformLink to FixIBM Aspera Console3.4.5
Windows click here https://www.ibm.com/support/fixcentral/swg/downloadFixes IBM Aspera Console3.4.5
Linux click here https://www.ibm.com/support/fixcentral/swg/downloadFixes
References (2)
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2022-46810 Advisory
- https://www.ibm.com/support/pages/node/7169766 vendor-advisorypatchVendor Advisory
| Link | Providers | Tags |
|---|---|---|
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2022-46810 | Advisory | |
| https://www.ibm.com/support/pages/node/7169766 | vendor-advisorypatchVendor Advisory |
Change history (0)
No recorded changes yet.