Cross-Site Request Forgery Vulnerability in IBM Aspera Orchestrator 4.0.1
CVE-2023-38001

6.5MEDIUM

Key Information:

Vendor
IBM
Vendor
CVE Published:
30 July 2024

Summary

IBM Aspera Orchestrator version 4.0.1 is exposed to a cross-site request forgery vulnerability that permits an attacker to execute unauthorized commands by exploiting the trust a website has for its users. This flaw enables malevolent actors to perform actions on behalf of authenticated users, compromising the integrity and security of operations facilitated by the affected product. Users and administrators should review the advisory and implement recommended patches and best practices to mitigate the threat associated with this vulnerability.

Affected Version(s)

Aspera Orchestrator 4.0.1

References

CVSS V3.1

Score:
6.5
Severity:
MEDIUM
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.