Vulnerabilities > IBM > Aspera Faspex > 5.0.0

DATE CVE VULNERABILITY TITLE RISK
2024-04-19 CVE-2022-40745 Inadequate Encryption Strength vulnerability in IBM Aspera Faspex
IBM Aspera Faspex 5.0.0 through 5.0.7 could allow a local user to obtain sensitive information due to weaker than expected security.
local
low complexity
ibm CWE-326
5.5
2024-04-19 CVE-2023-27279 Unspecified vulnerability in IBM Aspera Faspex
IBM Aspera Faspex 5.0.0 through 5.0.7 could allow a user to cause a denial of service due to missing API rate limiting.
network
low complexity
ibm
6.5
2024-04-19 CVE-2023-37397 Inadequate Encryption Strength vulnerability in IBM Aspera Faspex
IBM Aspera Faspex 5.0.0 through 5.0.7 could allow a local user to obtain or modify sensitive information due to improper encryption of certain data.
local
low complexity
ibm CWE-326
4.4
2024-02-02 CVE-2022-40744 Cross-site Scripting vulnerability in IBM Aspera Faspex
IBM Aspera Faspex 5.0.6 is vulnerable to stored cross-site scripting.
network
low complexity
ibm CWE-79
5.4
2023-09-08 CVE-2022-22401 Missing Encryption of Sensitive Data vulnerability in IBM Aspera Faspex 4.4.1/5.0.0
IBM Aspera Faspex 5.0.5 could allow a remote attacker to gather or persuade a naive user to supply sensitive information.
network
low complexity
ibm CWE-311
7.5
2023-09-08 CVE-2022-22402 Cross-site Scripting vulnerability in IBM Aspera Faspex 4.4.1/5.0.0
IBM Aspera Faspex 5.0.5 is vulnerable to cross-site scripting.
network
low complexity
ibm CWE-79
5.4
2023-09-08 CVE-2022-22409 Unspecified vulnerability in IBM Aspera Faspex 4.4.1/5.0.0
IBM Aspera Faspex 5.0.5 could allow a remote attacker to gather sensitive information about the web application, caused by an insecure configuration.
network
low complexity
ibm
5.3
2023-09-08 CVE-2022-22405 Missing Encryption of Sensitive Data vulnerability in IBM Aspera Faspex 4.4.1/5.0.0
IBM Aspera Faspex 5.0.5 could allow a remote attacker to obtain sensitive information, caused by the failure to properly enable HTTP Strict Transport Security.
network
high complexity
ibm CWE-311
5.9
2023-09-08 CVE-2023-24965 Exposure of Resource to Wrong Sphere vulnerability in IBM Aspera Faspex 4.4.1/5.0.0
IBM Aspera Faspex 5.0.5 does not restrict or incorrectly restricts access to a resource from an unauthorized actor.
network
low complexity
ibm CWE-668
5.3
2023-09-08 CVE-2023-30995 Incorrect Authorization vulnerability in IBM Aspera Faspex
IBM Aspera Faspex 4.0 through 4.4.2 and 5.0 through 5.0.5 could allow a malicious actor to bypass IP whitelist restrictions using a specially crafted HTTP request.
network
low complexity
ibm CWE-863
7.5