Show filters
37 Total Results
Displaying 11-20 of 37
Sort by:
Attacker Value
Unknown

CVE-2023-37397

Disclosure Date: April 19, 2024 (last updated April 30, 2024)
IBM Aspera Faspex 5.0.0 through 5.0.7 could allow a local user to obtain or modify sensitive information due to improper encryption of certain data. IBM X-Force ID: 259672.
Attacker Value
Unknown

CVE-2023-27279

Disclosure Date: April 19, 2024 (last updated April 30, 2024)
IBM Aspera Faspex 5.0.0 through 5.0.7 could allow a user to cause a denial of service due to missing API rate limiting. IBM X-Force ID: 248533.
Attacker Value
Unknown

CVE-2022-40745

Disclosure Date: April 19, 2024 (last updated April 30, 2024)
IBM Aspera Faspex 5.0.0 through 5.0.7 could allow a local user to obtain sensitive information due to weaker than expected security. IBM X-Force ID: 236452.
Attacker Value
Unknown

CVE-2023-37396

Disclosure Date: April 19, 2024 (last updated December 20, 2024)
IBM Aspera Faspex 5.0.0 through 5.0.7 could allow a local user to obtain sensitive information due to improper encryption of certain data. IBM X-Force ID: 259671.
Attacker Value
Unknown

CVE-2023-22869

Disclosure Date: April 19, 2024 (last updated December 20, 2024)
IBM Aspera Faspex 5.0.0 through 5.0.7 stores potentially sensitive information in log files that could be read by a local user. IBM X-Force ID: 244119.
Attacker Value
Unknown

CVE-2023-37400

Disclosure Date: April 19, 2024 (last updated December 20, 2024)
IBM Aspera Faspex 5.0.0 through 5.0.7 could allow a local user to escalate their privileges due to insecure credential storage. IBM X-Force ID: 259677.
Attacker Value
Unknown

CVE-2022-22399

Disclosure Date: March 05, 2024 (last updated January 15, 2025)
IBM Aspera Faspex 5.0.0 and 5.0.1 is vulnerable to HTTP header injection, caused by improper validation of input by the HOST headers. This could allow an attacker to conduct various attacks against the vulnerable system, including cross-site scripting, cache poisoning or session hijacking. IBM X-Force ID: 222562.
Attacker Value
Unknown

CVE-2022-40744

Disclosure Date: February 02, 2024 (last updated February 10, 2024)
IBM Aspera Faspex 5.0.6 is vulnerable to stored cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 236441.
Attacker Value
Unknown

CVE-2022-22409

Disclosure Date: September 08, 2023 (last updated October 08, 2023)
IBM Aspera Faspex 5.0.5 could allow a remote attacker to gather sensitive information about the web application, caused by an insecure configuration. IBM X-Force ID: 222592.
Attacker Value
Unknown

CVE-2022-22402

Disclosure Date: September 08, 2023 (last updated October 08, 2023)
IBM Aspera Faspex 5.0.5 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 222571.