Lucene search

K
ibmIBM57085FA168ACA7EEF5C6C73D16F485FA7A4B1491367D8CB50B4D5770F2162820
HistoryMay 02, 2024 - 9:30 p.m.

Security Bulletin: IBM Aspera Orchestrator affected by a command injection vulnerability (CVE-2023-37407)

2024-05-0221:30:52
www.ibm.com
11
ibm aspera orchestrator
command injection vulnerability
cve-2023-37407
remote authenticated attacker
arbitrary commands
cvss base score
linux
ibm aspera orchestrator 4.0.1
security fix

CVSS3

8.8

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

AI Score

8.1

Confidence

High

EPSS

0

Percentile

9.6%

Summary

IBM Aspera Orchestrator has addressed a vulnerability that could allow execution of arbitrary code (CVE-2023-37407).

Vulnerability Details

CVEID:CVE-2023-37407
**DESCRIPTION:**IBM Aspera Orchestrator could allow a remote authenticated attacker to execute arbitrary commands on the system by sending a specially crafted request.
CVSS Base score: 8.8
CVSS Temporal Score: See: https://exchange.xforce.ibmcloud.com/vulnerabilities/260116 for the current score.
CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H)

Affected Products and Versions

Affected Product(s) Version(s)
IBM Aspera Orchestrator 4.0.1

Remediation/Fixes

IBM strongly recommends addressing the vulnerability now by applying the below fix as soon as possible:

Product Version Platform Link to Fix
IBM Aspera Orchestrator 4.0.1 PL1/PL2 Linux click here

Workarounds and Mitigations

None

Affected configurations

Vulners
Node
ibmaspera_orchestratorMatch4.0.0
OR
ibmaspera_orchestratorMatch4.0.1
VendorProductVersionCPE
ibmaspera_orchestrator4.0.0cpe:2.3:a:ibm:aspera_orchestrator:4.0.0:*:*:*:*:*:*:*
ibmaspera_orchestrator4.0.1cpe:2.3:a:ibm:aspera_orchestrator:4.0.1:*:*:*:*:*:*:*

CVSS3

8.8

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

AI Score

8.1

Confidence

High

EPSS

0

Percentile

9.6%

Related for 57085FA168ACA7EEF5C6C73D16F485FA7A4B1491367D8CB50B4D5770F2162820