CVE-2023-27874 – IBM Aspera Faspex XML external entity injection
https://notcve.org/view.php?id=CVE-2023-27874
IBM Aspera Faspex 4.4.2 is vulnerable to an XML external entity injection (XXE) attack when processing XML data. A remote authenticated attacker could exploit this vulnerability to execute arbitrary commands. IBM X-Force ID: 249845. • https://exchange.xforce.ibmcloud.com/vulnerabilities/249845 https://www.ibm.com/support/pages/node/6964694 • CWE-611: Improper Restriction of XML External Entity Reference •
CVE-2023-27871 – IBM Aspera Faspex information disclosure
https://notcve.org/view.php?id=CVE-2023-27871
IBM Aspera Faspex 4.4.2 could allow a remote attacker to obtain sensitive credential information for an external user, using a specially crafted SQL query. IBM X-Force ID: 249613. • https://exchange.xforce.ibmcloud.com/vulnerabilities/249613 https://www.ibm.com/support/pages/node/6964694 • CWE-89: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') •
CVE-2023-27875 – IBM Aspera Faspex improper access controls
https://notcve.org/view.php?id=CVE-2023-27875
IBM Aspera Faspex 5.0.4 could allow a user to change other user's credentials due to improper access controls. IBM X-Force ID: 249847. • https://exchange.xforce.ibmcloud.com/vulnerabilities/249847 https://www.ibm.com/support/pages/node/6963662 •
CVE-2023-22591 – IBM Robotic Process Automation session fixation
https://notcve.org/view.php?id=CVE-2023-22591
IBM Robotic Process Automation 21.0.1 through 21.0.7 and 23.0.0 through 23.0.1 could allow a user with physical access to the system due to session tokens for not being invalidated after a password reset. IBM X-Force ID: 243710. • https://exchange.xforce.ibmcloud.com/vulnerabilities/243710 https://www.ibm.com/support/pages/node/6962175 • CWE-613: Insufficient Session Expiration •
CVE-2022-46773 – IBM Robotic Process Automation security bypass
https://notcve.org/view.php?id=CVE-2022-46773
IBM Robotic Process Automation 21.0.0 - 21.0.7 and 23.0.0 is vulnerable to client-side validation bypass for credential pools. Invalid credential pools may be created as a result. IBM X-Force ID: 242951. • https://exchange.xforce.ibmcloud.com/vulnerabilities/242951 https://www.ibm.com/support/pages/node/6962155 • CWE-287: Improper Authentication •