Show filters
37 Total Results
Displaying 1-10 of 37
Sort by:
Attacker Value
Very High

CVE-2022-47986

Disclosure Date: February 17, 2023 (last updated February 14, 2025)
IBM Aspera Faspex 4.4.2 Patch Level 1 and earlier could allow a remote attacker to execute arbitrary code on the system, caused by a YAML deserialization flaw. By sending a specially crafted obsolete API call, an attacker could exploit this vulnerability to execute arbitrary code on the system. The obsolete API call was removed in Faspex 4.4.2 PL2. IBM X-Force ID: 243512.
Attacker Value
Unknown

CVE-2023-37413

Disclosure Date: January 29, 2025 (last updated January 30, 2025)
IBM Aspera Faspex 5.0.0 through 5.0.10 could disclose sensitive username information due to an observable response discrepancy.
Attacker Value
Unknown

CVE-2023-37412

Disclosure Date: January 29, 2025 (last updated January 30, 2025)
IBM Aspera Faspex 5.0.0 through 5.0.10 could allow a privileged user to make system changes without proper access controls.
Attacker Value
Unknown

CVE-2023-37398

Disclosure Date: January 29, 2025 (last updated January 30, 2025)
IBM Aspera Faspex 5.0.0 through 5.0.10 does not require that users should have strong passwords by default, which makes it easier for attackers to compromise user accounts.
Attacker Value
Unknown

CVE-2023-35907

Disclosure Date: January 29, 2025 (last updated January 30, 2025)
IBM Aspera Faspex 5.0.0 through 5.0.10 does not require that users should have strong passwords by default, which makes it easier for attackers to compromise user accounts.
Attacker Value
Unknown

CVE-2023-37395

Disclosure Date: December 11, 2024 (last updated January 13, 2025)
IBM Aspera Faspex 5.0.0 through 5.0.7 could allow a local user to obtain sensitive information due to improper encryption of certain data.
Attacker Value
Unknown

CVE-2024-45098

Disclosure Date: September 05, 2024 (last updated September 07, 2024)
IBM Aspera Faspex 5.0.0 through 5.0.9 could allow a user to bypass intended access restrictions and conduct resource modification.
Attacker Value
Unknown

CVE-2024-45097

Disclosure Date: September 05, 2024 (last updated September 07, 2024)
IBM Aspera Faspex 5.0.0 through 5.0.9 could allow a user to bypass intended access restrictions and conduct resource modification.
Attacker Value
Unknown

CVE-2024-45096

Disclosure Date: September 05, 2024 (last updated September 07, 2024)
IBM Aspera Faspex 5.0.0 through 5.0.9 could allow a user with access to the package to obtain sensitive information through a directory listing.
Attacker Value
Unknown

CVE-2023-37411

Disclosure Date: May 28, 2024 (last updated January 15, 2025)
IBM Aspera Faspex 5.0.0 through 5.0.6 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 260139.