Vulnerabilities > IBM > Aspera Faspex

DATE CVE VULNERABILITY TITLE RISK
2024-04-19 CVE-2023-37400 Unspecified vulnerability in IBM Aspera Faspex
IBM Aspera Faspex 5.0.0 through 5.0.7 could allow a local user to escalate their privileges due to insecure credential storage.
local
low complexity
ibm
7.8
2024-03-05 CVE-2022-22399 Improper Encoding or Escaping of Output vulnerability in IBM Aspera Faspex 5.0.0/5.0.1
IBM Aspera Faspex 5.0.0 and 5.0.1 is vulnerable to HTTP header injection, caused by improper validation of input by the HOST headers.
network
low complexity
ibm CWE-116
6.5
2024-02-02 CVE-2022-40744 Unspecified vulnerability in IBM Aspera Faspex
IBM Aspera Faspex 5.0.6 is vulnerable to stored cross-site scripting.
network
low complexity
ibm
5.4
2023-09-08 CVE-2022-22401 Missing Encryption of Sensitive Data vulnerability in IBM Aspera Faspex
IBM Aspera Faspex 5.0.5 could allow a remote attacker to gather or persuade a naive user to supply sensitive information.
network
low complexity
ibm CWE-311
7.5
2023-09-08 CVE-2022-22402 Cross-site Scripting vulnerability in IBM Aspera Faspex
IBM Aspera Faspex 5.0.5 is vulnerable to cross-site scripting.
network
low complexity
ibm CWE-79
5.4
2023-09-08 CVE-2022-22409 Unspecified vulnerability in IBM Aspera Faspex
IBM Aspera Faspex 5.0.5 could allow a remote attacker to gather sensitive information about the web application, caused by an insecure configuration.
network
low complexity
ibm
5.3
2023-09-08 CVE-2022-22405 Missing Encryption of Sensitive Data vulnerability in IBM Aspera Faspex
IBM Aspera Faspex 5.0.5 could allow a remote attacker to obtain sensitive information, caused by the failure to properly enable HTTP Strict Transport Security.
network
high complexity
ibm CWE-311
5.9
2023-09-08 CVE-2023-24965 Exposure of Resource to Wrong Sphere vulnerability in IBM Aspera Faspex
IBM Aspera Faspex 5.0.5 does not restrict or incorrectly restricts access to a resource from an unauthorized actor.
network
low complexity
ibm CWE-668
5.3
2023-09-08 CVE-2023-30995 Incorrect Authorization vulnerability in IBM Aspera Faspex
IBM Aspera Faspex 4.0 through 4.4.2 and 5.0 through 5.0.5 could allow a malicious actor to bypass IP whitelist restrictions using a specially crafted HTTP request.
network
low complexity
ibm CWE-863
7.5
2023-09-05 CVE-2023-22870 Cleartext Transmission of Sensitive Information vulnerability in IBM Aspera Faspex
IBM Aspera Faspex 5.0.5 transmits sensitive information in cleartext which could be obtained by an attacker using man in the middle techniques.
network
high complexity
ibm CWE-319
5.9