Aspera Orchestrator 4.0.1 Vulnerability Could Enable Remote Username Enumeration
CVE-2023-27283
5.3MEDIUM
Summary
The vulnerability in IBM Aspera Orchestrator version 4.0.1 enables remote attackers to enumerate usernames by exploiting observable discrepancies in application responses. When attackers send specific requests, the differences in response times or content can be leveraged to infer valid usernames, leading to further security risks. Organizations using this version should assess their exposure and take appropriate measures to mitigate the potential exploitation of this vulnerability.
Affected Version(s)
Aspera Orchestrator 4.0.1
References
CVSS V3.1
Score:
5.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved