Description
IBM Aspera Console 3.4.0 through 3.4.4 could allow a remote authenticated attacker to execute arbitrary code on the system, caused by a CSV injection vulnerability. By persuading a victim to open a specially crafted file, an attacker could exploit this vulnerability to execute arbitrary code on the system.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2021-25400 | IBM Aspera Console 3.4.0 through 3.4.4 could allow a remote authenticated attacker to execute arbitrary code on the system, caused by a CSV injection vulnerability. By persuading a victim to open a specially crafted file, an attacker could exploit this vulnerability to execute arbitrary code on the system. |
References
| Link | Providers |
|---|---|
| https://www.ibm.com/support/pages/node/7169765 |
|
History
Mon, 30 Sep 2024 16:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Linux
Linux linux Kernel Microsoft Microsoft windows |
|
| CPEs | cpe:2.3:a:ibm:aspera_console:*:*:*:*:*:*:*:* cpe:2.3:o:linux:linux_kernel:-:*:*:*:*:*:*:* cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:*:* |
|
| Vendors & Products |
Linux
Linux linux Kernel Microsoft Microsoft windows |
Tue, 24 Sep 2024 14:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 24 Sep 2024 10:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | IBM Aspera Console 3.4.0 through 3.4.4 could allow a remote authenticated attacker to execute arbitrary code on the system, caused by a CSV injection vulnerability. By persuading a victim to open a specially crafted file, an attacker could exploit this vulnerability to execute arbitrary code on the system. | |
| Title | IBM Aspera Console CSV injection | |
| First Time appeared |
Ibm
Ibm aspera Console |
|
| Weaknesses | CWE-1236 | |
| CPEs | cpe:2.3:a:ibm:aspera_console:3.4.0:*:*:*:*:*:*:* cpe:2.3:a:ibm:aspera_console:3.4.4:*:*:*:*:*:*:* |
|
| Vendors & Products |
Ibm
Ibm aspera Console |
|
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: ibm
Published:
Updated: 2024-09-24T13:49:57.213Z
Reserved: 2021-08-16T18:59:46.192Z
Link: CVE-2021-38963
Updated: 2024-09-24T13:49:53.660Z
Status : Analyzed
Published: 2024-09-25T01:15:26.607
Modified: 2024-09-30T15:48:54.707
Link: CVE-2021-38963
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD