XPath Injection Vulnerability in IBM Aspera Console
CVE-2022-43840
4.3MEDIUM
What is CVE-2022-43840?
IBM Aspera Console versions 3.4.0 to 3.4.4 are susceptible to an XPath injection vulnerability. This security flaw could enable authenticated attackers to access sensitive application data and gain insights into the structure of the XML document, potentially leading to further exploitation. Users are advised to review their implementations and apply necessary updates to mitigate this vulnerability.
Affected Version(s)
Aspera Console 3.4.0 <= 3.4.4