IBM Aspera Console XPath Injection Vulnerability Allowing Data Exfiltration

Vulnerability

A XPath injection vulnerability has been identified in IBM Aspera Console versions 3.4.0 to 3.4.4. This vulnerability allows authenticated attackers to exfiltrate sensitive application data or determine the structure of the XML document.

Impact

Exploitation of this vulnerability could lead to unauthorized exfiltration of sensitive application data or manipulation of the application's XML data structure.

Remediation

Users are advised to upgrade to IBM Aspera Console version 3.4.5, available for both Windows and Linux.

Added: Jun 9, 2025, 7:46 PM
Updated: Jun 9, 2025, 7:46 PM

Vulnerability Rating

Custom Algorithm
spread
2.6
impact
2.5
exploitability
4.9
remediation
7.7
relevance
0.0
threat
0.0
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.