Aspera Orchestrator Vulnerable to HTTP Header Injection
CVE-2023-26289
5.4MEDIUM
What is CVE-2023-26289?
IBM Aspera Orchestrator 4.0.1 contains a vulnerability due to insufficient validation of input in HOST headers, which may allow an attacker to exploit this weakness through various attacks. Potential threats include cross-site scripting, cache poisoning, and session hijacking, which could compromise the integrity and confidentiality of user data within the affected systems. Organizations utilizing this product should assess their exposure and implement necessary mitigations promptly to protect against these threats.
Affected Version(s)
Aspera Orchestrator 4.0.1