Home
MEDIUM: 4.3 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:NDefault status
unaffected
3.4.0 (semver)
affected
Description
IBM Aspera Console 3.4.0 through 3.4.4 is vulnerable to an XPath injection vulnerability, which could allow an authenticated attacker to exfiltrate sensitive application data and/or determine the structure of the XML document.
Problem types
CWE-643 Improper Neutralization of Data within XPath Expressions ('XPath Injection')
Product status
3.4.0 (semver)
References
www.ibm.com/support/pages/node/7169766