Show filters
37 Total Results
Displaying 1-10 of 37
Sort by:
Attacker Value
Very High
CVE-2022-47986
Disclosure Date: February 17, 2023 (last updated February 14, 2025)
IBM Aspera Faspex 4.4.2 Patch Level 1 and earlier could allow a remote attacker to execute arbitrary code on the system, caused by a YAML deserialization flaw. By sending a specially crafted obsolete API call, an attacker could exploit this vulnerability to execute arbitrary code on the system. The obsolete API call was removed in Faspex 4.4.2 PL2. IBM X-Force ID: 243512.
3
Attacker Value
Unknown
CVE-2023-37413
Disclosure Date: January 29, 2025 (last updated January 30, 2025)
IBM Aspera Faspex 5.0.0 through 5.0.10 could disclose sensitive username information due to an observable response discrepancy.
0
Attacker Value
Unknown
CVE-2023-37412
Disclosure Date: January 29, 2025 (last updated January 30, 2025)
IBM Aspera Faspex 5.0.0 through 5.0.10 could allow a privileged user to make system changes without proper access controls.
0
Attacker Value
Unknown
CVE-2023-37398
Disclosure Date: January 29, 2025 (last updated January 30, 2025)
IBM Aspera Faspex 5.0.0 through 5.0.10 does not require that users should have strong passwords by default, which makes it easier for attackers to compromise user accounts.
0
Attacker Value
Unknown
CVE-2023-35907
Disclosure Date: January 29, 2025 (last updated January 30, 2025)
IBM Aspera Faspex 5.0.0 through 5.0.10 does not require that users should have strong passwords by default, which makes it easier for attackers to compromise user accounts.
0
Attacker Value
Unknown
CVE-2023-37395
Disclosure Date: December 11, 2024 (last updated January 13, 2025)
IBM Aspera Faspex 5.0.0 through 5.0.7 could allow a local user to obtain sensitive information due to improper encryption of certain data.
0
Attacker Value
Unknown
CVE-2024-45098
Disclosure Date: September 05, 2024 (last updated September 07, 2024)
IBM Aspera Faspex 5.0.0 through 5.0.9 could allow a user to bypass intended access restrictions and conduct resource modification.
0
Attacker Value
Unknown
CVE-2024-45097
Disclosure Date: September 05, 2024 (last updated September 07, 2024)
IBM Aspera Faspex 5.0.0 through 5.0.9 could allow a user to bypass intended access restrictions and conduct resource modification.
0
Attacker Value
Unknown
CVE-2024-45096
Disclosure Date: September 05, 2024 (last updated September 07, 2024)
IBM Aspera Faspex 5.0.0 through 5.0.9 could allow a user with access to the package to obtain sensitive information through a directory listing.
0
Attacker Value
Unknown
CVE-2023-37411
Disclosure Date: May 28, 2024 (last updated January 15, 2025)
IBM Aspera Faspex 5.0.0 through 5.0.6 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 260139.
0